Unauthenticated Broken Access Control in Robokassa Payment Gateway for WooCommerce
CVE-2026-78536
6.5MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 10 September 2026
What is CVE-2026-78536?
The Robokassa payment gateway for WooCommerce versions up to 1.8.9 is susceptible to unauthenticated broken access control. This vulnerability allows unauthorized users to gain access to sensitive functions and data within the plugin, potentially compromising the integrity of payment processes and user information. It is critical for users of affected versions to implement immediate updates to safeguard their websites against potential exploitation.
Affected Version(s)
Robokassa payment gateway for Woocommerce <= 1.8.9