Robokassa payment gateway for Woocommerce <= 1.8.9 - Unauthenticated Insecure Direct Object Reference to Order Key Exposure via 'InvId' Parameter

Low 3.7 CWE-639Fixed in 1.9.0
ID
WPSEC-2026-0596
Plugin
Robokassa payment gateway for Woocommerce (robokassa)
Affected
all versions before 1.9.0
Remediation
Update to 1.9.0 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Weakness
CWE-639
Usage
Plugin Low · Affected versions None seen among sites WPSec scans, 2026-10-07
Attack surface
Robokassa payment gateway for Woocommerce on WPSec AttackSurface
Fix released
Published

Description

The Robokassa payment gateway for Woocommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.8.9 via the payment success and fail redirect endpoints, which build an order-specific redirect URL from the unsigned, user-supplied 'InvId' parameter. This makes it possible for unauthenticated attackers to obtain the order-received URL, including the order key, of arbitrary orders and, where WooCommerce does not require further verification, view those orders' details.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0