Executive brief
ЮKassa для WooCommerce is a WordPress plugin that enables online payment processing for e-commerce stores. A security flaw in versions 2.16.1 and earlier allows users with basic 'Subscriber' accounts to perform actions they should not be authorized to access. While the risk is considered low, it could allow unauthorized changes to certain site settings or data, potentially interfering with store operations.
Technical details
A broken access control vulnerability exists in the ЮKassa для WooCommerce plugin for WordPress (versions <= 2.16.1) due to missing authorization checks (CWE-862). An attacker authenticated with low-level 'Subscriber' privileges can exploit this flaw over the network to execute functions or modify settings that should be restricted to higher-privileged users. The vulnerability was addressed in version 2.16.2 by implementing proper authorization validation. The CVSS score of 4.3 reflects that while the attack is easy to execute, the impact is limited to integrity without affecting confidentiality or availability.
Affected products
- YooMoney ЮKassa для WooCommerce (YooKassa) <= 2.16.1
Timeline
- 2026-06-12: other: Reported by researcher Ananda Dhakal
- 2026-07-22: advisory: Patchstack advisory published
- 2026-07-23: disclosed: CVE published to NVD
- 2026-07-23: patched: Fixed in version 2.16.2