PatchSiren cyber security CVE debrief
CVE-2026-91017 Robokassa CVE debrief
The Robokassa payment gateway for Woocommerce WordPress plugin before 1.8.9 does not verify the authenticity of incoming payment notifications when its non-default deferred-payment feature is enabled, allowing unauthenticated attackers to forge a notification and mark arbitrary WooCommerce orders as paid or on-hold without payment or a valid signature.
- Vendor
- Robokassa
- Product
- Robokassa payment gateway for Woocommerce
- CVSS
- LOW 3.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-17
- Original CVE updated
- 2026-09-18
- Advisory published
- 2026-09-17
- Advisory updated
- 2026-09-18
Who should care
Defenders responsible for Woocommerce WordPress plugin installations with the Robokassa payment gateway should assess exposure and prioritize verification and remediation. They need to verify the authenticity of payment notifications to prevent unauthorized modifications to WooCommerce orders. Updating to version 1.8.9 or later may mitigate the vulnerability. Monitoring for suspicious payment activity can help detect potential exploitation attempts.
Why it matters
CVE-2026-91017 is a vulnerability in the Robokassa payment gateway for Woocommerce WordPress plugin that allows unauthenticated attackers to forge payment notifications and modify WooCommerce orders. Defenders should prioritize verification and remediation to prevent potential exploitation.
- Defenders need to verify the authenticity of payment notifications to prevent unauthorized modifications to WooCommerce orders.
- Updating to version 1.8.9 or later may mitigate the vulnerability.
- Monitoring for suspicious payment activity can help detect potential exploitation attempts.
Technical summary
The Robokassa payment gateway for Woocommerce WordPress plugin before 1.8.9 does not verify the authenticity of incoming payment notifications when its non-default deferred-payment feature is enabled, allowing unauthenticated attackers to forge a notification and mark arbitrary WooCommerce orders as paid or on-hold without payment or a valid signature. This vulnerability affects defenders responsible for Woocommerce WordPress plugin installations with the Robokassa payment gateway, who should prioritize verifying the authenticity of payment notifications and updating to version 1.8.9 or later.
Defensive priority
Defenders should prioritize verifying the authenticity of payment notifications and updating to version 1.8.9 or later.
Recommended defensive actions
- Verify the authenticity of payment notifications
- Update to version 1.8.9 or later
- Monitor for suspicious payment activity
- Review compensating controls for exposed systems
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, but further verification is needed to determine the scope of affected systems and the effectiveness of the fix. The vulnerability affects the Robokassa payment gateway for Woocommerce WordPress plugin before version 1.8.9. Defenders should verify the authenticity of payment notifications and review compensating controls for exposed systems while remediation is scheduled and verified.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-91017 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-91017
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-91017 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-91017
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://wpscan.com/vulnerability/1aeef0b4-9b14-4b03-b7f6-a05937622023/
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.