Payment Notification Forgery in Robokassa WooCommerce Plugin
CVE-2026-91017
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 17 September 2026
Badges
What is CVE-2026-91017?
The Robokassa payment gateway for the WooCommerce WordPress plugin, prior to version 1.8.9, contains a flaw that fails to adequately authenticate incoming payment notifications when the non-default deferred-payment feature is enabled. This allows unauthorized attackers to manipulate payment notifications, effectively marking WooCommerce orders as paid or on-hold without any legitimate authorization or valid signature, posing a significant risk to merchants using this plugin.
Affected Version(s)
Robokassa payment gateway for Woocommerce 0 < 1.8.9
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved