Executive brief
The Robokassa payment gateway plugin for WooCommerce allows unauthenticated users to access pages and perform payment-related actions they should not be permitted to execute. This broken access control vulnerability could enable attackers to bypass security checks, potentially viewing or manipulating order and payment data without proper authorization.
Technical details
The vulnerability is a broken access control flaw in the Robokassa payment gateway plugin for WooCommerce versions 1.8.9 and earlier, where the plugin fails to properly validate user permissions before granting access to sensitive operations. The flaw is unauthenticated, meaning an attacker does not need valid credentials to trigger the vulnerability. The attack is network-accessible without requiring user interaction or special privileges. An attacker can exploit this to access or manipulate pages and perform actions restricted to authorized users. No official patch has been released at the time of disclosure.
Affected products
- Robokassa Robokassa payment gateway for WooCommerce <=1.8.9
Timeline
- 2026-09-10: disclosed: Published by Patchstack
- 2026-04-30: other: Initially reported by HaiND