Vulnerabilities and security researches forrobokassa robokassa
Direction: descendingSep 19, 2026
Robokassa payment gateway for Woocommerce # CVE-2026-91017
- CVE, Research URL
- Application
- Date
- Sep 17, 2026
- Research Description
- The Robokassa payment gateway for Woocommerce WordPress plugin before 1.8.9 does not verify the authenticity of incoming payment notifications when its non-default deferred-payment feature is enabled, allowing unauthenticated attackers to forge a notification and mark arbitrary WooCommerce orders as paid or on-hold without payment or a valid signature.
- Affected versions
-
max 1.8.9.
- Status
-
vulnerable
Sep 12, 2026
Robokassa payment gateway for Woocommerce # CVE-2026-78536
- CVE, Research URL
- Application
- Date
- Sep 10, 2026
- Research Description
- Unauthenticated Broken Access Control in Robokassa payment gateway for Woocommerce <= 1.8.9 versions.
- Affected versions
-
max 1.8.9.
- Status
-
vulnerable
Jun 16, 2026
Robokassa payment gateway for Woocommerce # 2764b12fb02f16675d4361e5cfa9b3491fea2177
- CVE, Research URL
- Application
- Date
- Apr 19, 2023
- Research Description
- Robokassa payment gateway for Woocommerce [robokassa] < 1.4.6 Robokassa payment gateway for Woocommerce <= 1.4.5 - Authenticated (Administrator+) Stored Cross-Site Scripting The Robokassa payment gateway for Woocommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 1.4.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.
- Affected versions
-
max 1.4.6.
- Status
-
vulnerable
Nov 11, 2025
Robokassa payment gateway for Woocommerce # CVE-2025-49958
- CVE, Research URL
- Application
- Date
- Oct 22, 2025
- Research Description
- Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in robokassa Robokassa payment gateway for Woocommerce robokassa allows Reflected XSS.This issue affects Robokassa payment gateway for Woocommerce: from n/a through <= 1.8.6.
- Affected versions
-
max 1.8.6.
- Status
-
vulnerable
Oct 03, 2024
Robokassa payment gateway for Woocommerce # CVE-2024-47395
- CVE, Research URL
- Application
- Date
- Oct 05, 2024
- Research Description
- Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in robokassa Robokassa payment gateway for Woocommerce robokassa allows Reflected XSS.This issue affects Robokassa payment gateway for Woocommerce: from n/a through <= 1.6.1.
- Affected versions
-
max 1.6.2.
- Status
-
vulnerable
Jun 07, 2024
Robokassa payment gateway for Woocommerce # 460912a86cae6b7eebf28bf2d66b27d6b124510f
- CVE, Research URL
- Application
- Date
- Apr 20, 2023
- Research Description
- Robokassa payment gateway for Woocommerce [robokassa] < 1.4.6 WordPress Robokassa payment gateway for Woocommerce Plugin <= 1.4.5 is vulnerable to Cross Site Scripting (XSS) Update the WordPress Robokassa payment gateway for Woocommerce plugin to the latest available version (at least 1.4.6). An unknown person discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Robokassa payment gateway for Woocommerce Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 1.4.6.
- Affected versions
-
max 1.4.6.
- Status
-
vulnerable