Back

LOW

Robokassa payment gateway for Woocommerce < 1.8.9 - Unauthenticated Payment Bypass via Forged JWT Callback

Published Sep 17, 2026

Description

The Robokassa payment gateway for Woocommerce WordPress plugin before 1.8.9 does not verify the authenticity of incoming payment notifications when its non-default deferred-payment feature is enabled, allowing unauthenticated attackers to forge a notification and mark arbitrary WooCommerce orders as paid or on-hold without payment or a valid signature.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (2)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner WPScan
Published Sep 17, 2026
Updated Sep 17, 2026
Reserved Sep 14, 2026

CISA Vulnrichment

Updated Sep 17, 2026

NVD

Status Deferred
Modified Sep 18, 2026

Red Hat

No data

ENISA EUVD

Assigner WPScan
Published Sep 17, 2026
Updated Sep 17, 2026

GitHub

No data