CVE-2026-91017 - Robokassa payment gateway for Woocommerce < 1.8.9 - Unauthenticated Payment Bypass via Forged JWT Callback
CVE ID :CVE-2026-91017
Published : Sept. 17, 2026, 7:16 a.m. | 3 hours, 52 minutes ago
Description :The Robokassa payment gateway for Woocommerce WordPress plugin before 1.8.9 does not verify the authenticity of incoming payment notifications when its non-default deferred-payment feature is enabled, allowing unauthenticated attackers to forge a notification and mark arbitrary WooCommerce orders as paid or on-hold without payment or a valid signature.
Severity: 3.7 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Sept. 17, 2026, 7:16 a.m. | 3 hours, 52 minutes ago
Description :The Robokassa payment gateway for Woocommerce WordPress plugin before 1.8.9 does not verify the authenticity of incoming payment notifications when its non-default deferred-payment feature is enabled, allowing unauthenticated attackers to forge a notification and mark arbitrary WooCommerce orders as paid or on-hold without payment or a valid signature.
Severity: 3.7 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...