cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forrobokassa robokassa

Direction: descending
Sep 19, 2026

Robokassa payment gateway for Woocommerce # CVE-2026-91017

CVE, Research URL

CVE-2026-91017

Date
Sep 17, 2026
Research Description
The Robokassa payment gateway for Woocommerce WordPress plugin before 1.8.9 does not verify the authenticity of incoming payment notifications when its non-default deferred-payment feature is enabled, allowing unauthenticated attackers to forge a notification and mark arbitrary WooCommerce orders as paid or on-hold without payment or a valid signature.
Affected versions
max 1.8.9.
Status
vulnerable
Sep 12, 2026

Robokassa payment gateway for Woocommerce # CVE-2026-78536

CVE, Research URL

CVE-2026-78536

Date
Sep 10, 2026
Research Description
Unauthenticated Broken Access Control in Robokassa payment gateway for Woocommerce <= 1.8.9 versions.
Affected versions
max 1.8.9.
Status
vulnerable
Jun 16, 2026

Robokassa payment gateway for Woocommerce # 2764b12fb02f16675d4361e5cfa9b3491fea2177

Date
Apr 19, 2023
Research Description
Robokassa payment gateway for Woocommerce [robokassa] < 1.4.6 Robokassa payment gateway for Woocommerce <= 1.4.5 - Authenticated (Administrator+) Stored Cross-Site Scripting The Robokassa payment gateway for Woocommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 1.4.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.
Affected versions
max 1.4.6.
Status
vulnerable
Nov 11, 2025

Robokassa payment gateway for Woocommerce # CVE-2025-49958

CVE, Research URL

CVE-2025-49958

Date
Oct 22, 2025
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in robokassa Robokassa payment gateway for Woocommerce robokassa allows Reflected XSS.This issue affects Robokassa payment gateway for Woocommerce: from n/a through <= 1.8.6.
Affected versions
max 1.8.6.
Status
vulnerable
Oct 03, 2024

Robokassa payment gateway for Woocommerce # CVE-2024-47395

CVE, Research URL

CVE-2024-47395

Date
Oct 05, 2024
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in robokassa Robokassa payment gateway for Woocommerce robokassa allows Reflected XSS.This issue affects Robokassa payment gateway for Woocommerce: from n/a through <= 1.6.1.
Affected versions
max 1.6.2.
Status
vulnerable
Jun 07, 2024

Robokassa payment gateway for Woocommerce # 460912a86cae6b7eebf28bf2d66b27d6b124510f

Date
Apr 20, 2023
Research Description
Robokassa payment gateway for Woocommerce [robokassa] < 1.4.6 WordPress Robokassa payment gateway for Woocommerce Plugin <= 1.4.5 is vulnerable to Cross Site Scripting (XSS) Update the WordPress Robokassa payment gateway for Woocommerce plugin to the latest available version (at least 1.4.6). An unknown person discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress Robokassa payment gateway for Woocommerce Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site. This vulnerability has been fixed in version 1.4.6.
Affected versions
max 1.4.6.
Status
vulnerable