PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-91017 Robokassa CVE debrief

The Robokassa payment gateway for Woocommerce WordPress plugin before 1.8.9 does not verify the authenticity of incoming payment notifications when its non-default deferred-payment feature is enabled, allowing unauthenticated attackers to forge a notification and mark arbitrary WooCommerce orders as paid or on-hold without payment or a valid signature.

Vendor
Robokassa
Product
Robokassa payment gateway for Woocommerce
CVSS
LOW 3.7
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-17
Original CVE updated
2026-09-18
Advisory published
2026-09-17
Advisory updated
2026-09-18

Who should care

Defenders responsible for Woocommerce WordPress plugin installations with the Robokassa payment gateway should assess exposure and prioritize verification and remediation. They need to verify the authenticity of payment notifications to prevent unauthorized modifications to WooCommerce orders. Updating to version 1.8.9 or later may mitigate the vulnerability. Monitoring for suspicious payment activity can help detect potential exploitation attempts.

Why it matters

CVE-2026-91017 is a vulnerability in the Robokassa payment gateway for Woocommerce WordPress plugin that allows unauthenticated attackers to forge payment notifications and modify WooCommerce orders. Defenders should prioritize verification and remediation to prevent potential exploitation.

  • Defenders need to verify the authenticity of payment notifications to prevent unauthorized modifications to WooCommerce orders.
  • Updating to version 1.8.9 or later may mitigate the vulnerability.
  • Monitoring for suspicious payment activity can help detect potential exploitation attempts.

Technical summary

The Robokassa payment gateway for Woocommerce WordPress plugin before 1.8.9 does not verify the authenticity of incoming payment notifications when its non-default deferred-payment feature is enabled, allowing unauthenticated attackers to forge a notification and mark arbitrary WooCommerce orders as paid or on-hold without payment or a valid signature. This vulnerability affects defenders responsible for Woocommerce WordPress plugin installations with the Robokassa payment gateway, who should prioritize verifying the authenticity of payment notifications and updating to version 1.8.9 or later.

Defensive priority

Defenders should prioritize verifying the authenticity of payment notifications and updating to version 1.8.9 or later.

Recommended defensive actions

  • Verify the authenticity of payment notifications
  • Update to version 1.8.9 or later
  • Monitor for suspicious payment activity
  • Review compensating controls for exposed systems
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, but further verification is needed to determine the scope of affected systems and the effectiveness of the fix. The vulnerability affects the Robokassa payment gateway for Woocommerce WordPress plugin before version 1.8.9. Defenders should verify the authenticity of payment notifications and review compensating controls for exposed systems while remediation is scheduled and verified.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-91017 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-91017

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-91017 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-91017

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.