---
id: CVE-2026-91017
title: >-
  The Robokassa payment gateway for Woocommerce WordPress plugin before 1.8.9
  does not verify the authenticity of incoming payment notifications when its
  non-default deferred-payment feature is enabled, allowing unauthenticated
  attackers t…
summary: >-
  The Robokassa payment gateway for Woocommerce WordPress plugin before 1.8.9
  does not verify the authenticity of incoming payment notifications when its
  non-default deferred-payment feature is enabled, allowing unauthenticated
  attackers t…
severity: low
cvss: 3.7
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N'
cwe:
  - CWE-345
product: Robokassa payment gateway for Woocommerce
affected:
  - robokassa_payment_gateway_for_woocommerce < 1.8.9
published: '2026-09-17'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T19:08:32.830'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-91017'
references:
  - url: 'https://wpscan.com/vulnerability/1aeef0b4-9b14-4b03-b7f6-a05937622023/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
epss: 0.00102
epssPercentile: 0.01034
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-17T12:09:22.630536Z'
ingestedAt: '2026-09-17T07:13:35.792Z'
---

## Overview

The Robokassa payment gateway for Woocommerce WordPress plugin before 1.8.9 does not verify the authenticity of incoming payment notifications when its non-default deferred-payment feature is enabled, allowing unauthenticated attackers to forge a notification and mark arbitrary WooCommerce orders as paid or on-hold without payment or a valid signature.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
