Vulnerabilities / Robokassa payment gateway for Woocommerce / WPSEC-2026-0596
Robokassa payment gateway for Woocommerce <= 1.8.9 - Unauthenticated Insecure Direct Object Reference to Order Key Exposure via 'InvId' Parameter
Low 3.7
CWE-639Fixed in 1.9.0
- ID
- WPSEC-2026-0596
- Plugin
- Robokassa payment gateway for Woocommerce (robokassa)
- Affected
- all versions before 1.9.0
- Remediation
- Update to 1.9.0 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
- Weakness
- CWE-639
- Usage
- Plugin Low · Affected versions None seen among sites WPSec scans, 2026-10-07
- Attack surface
- Robokassa payment gateway for Woocommerce on WPSec AttackSurface
- Fix released
- Published
Description
The Robokassa payment gateway for Woocommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.8.9 via the payment success and fail redirect endpoints, which build an order-specific redirect URL from the unsigned, user-supplied 'InvId' parameter. This makes it possible for unauthenticated attackers to obtain the order-received URL, including the order key, of arbitrary orders and, where WooCommerce does not require further verification, view those orders' details.
References
- https://wpsec.com/vuln/WPSEC-2026-0596/
- https://plugins.svn.wordpress.org/robokassa/tags/1.9.0/
- https://wordpress.org/plugins/robokassa/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS