Retour à la veille

CVE-2026-91017

Publié : 17 septembre 2026
Modifié : 17 septembre 2026
Lien officiel NVD
Score CVSS
3.7
LOW

Description détaillée

The Robokassa payment gateway for Woocommerce WordPress plugin before 1.8.9 does not verify the authenticity of incoming payment notifications when its non-default deferred-payment feature is enabled, allowing unauthenticated attackers to forge a notification and mark arbitrary WooCommerce orders as paid or on-hold without payment or a valid signature.

Vecteur d'attaque (CVSS)

Vecteur brut :CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N

Références et Patchs