Executive brief
The ЮKassa plugin for WooCommerce, which enables payment processing for online stores, contains a security flaw that exposes sensitive information. An individual with a basic user account (such as a customer or subscriber) could gain access to data they are not authorized to see. This exposure could lead to the theft of private business or customer information and may be used to facilitate further attacks on the website.
Technical details
The ЮKassa для WooCommerce plugin for WordPress is vulnerable to Sensitive Data Exposure (CWE-201) in versions up to 2.16.1. The vulnerability allows an authenticated attacker with 'Subscriber' level privileges to access sensitive information that should be restricted. This occurs due to improper protection of data sent or displayed by the plugin. An attacker can leverage this access to gather intelligence for further exploitation. The issue is addressed in version 2.16.2.
Affected products
- YooMoney ЮKassa для WooCommerce (YooKassa) <= 2.16.1
Timeline
- 2026-06-12: other: Reported by researcher Ananda Dhakal via Patchstack
- 2026-07-27: advisory: Advisory published by Patchstack and NVD
- 2026-07-27: patched: Patch released in version 2.16.2