{
 "id": "WPSEC-2026-0596",
 "url": "https://wpsec.com/vuln/WPSEC-2026-0596/",
 "json_url": "https://wpsec.com/vuln/WPSEC-2026-0596/advisory.json",
 "markdown_url": "https://wpsec.com/vuln/WPSEC-2026-0596/index.md",
 "title": "Robokassa payment gateway for Woocommerce <= 1.8.9 - Unauthenticated Insecure Direct Object Reference to Order Key Exposure via 'InvId' Parameter",
 "description": "The Robokassa payment gateway for Woocommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.8.9 via the payment success and fail redirect endpoints, which build an order-specific redirect URL from the unsigned, user-supplied 'InvId' parameter. This makes it possible for unauthenticated attackers to obtain the order-received URL, including the order key, of arbitrary orders and, where WooCommerce does not require further verification, view those orders' details.",
 "plugin": {
  "slug": "robokassa",
  "name": "Robokassa payment gateway for Woocommerce",
  "full_name": "Robokassa payment gateway for Woocommerce",
  "wordpress_org": "https://wordpress.org/plugins/robokassa/",
  "advisories_url": "https://wpsec.com/vuln/plugin/robokassa/",
  "attacksurface": "https://attacksurface.wpsec.com/plugin/robokassa"
 },
 "type": "AUTHBYPASS",
 "cwe": [
  "CWE-639"
 ],
 "cve": [],
 "cvss": {
  "version": "3.1",
  "score": 3.7,
  "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N",
  "severity": "Low"
 },
 "affected": {
  "ranges": [
   {
    "from": null,
    "from_inclusive": true,
    "to": "1.9.0",
    "to_inclusive": false
   }
  ],
  "text": [
   "all versions before 1.9.0"
  ]
 },
 "introduced_in": null,
 "fixed_in": "1.9.0",
 "remediation": "Update to 1.9.0 or later.",
 "fix_released": "2026-10-05T09:31:43+00:00",
 "published": "2026-10-07T19:47:10+00:00",
 "updated": "2026-10-07T19:15:24.060273+00:00",
 "also_published_as": null,
 "references": [
  "https://wpsec.com/vuln/WPSEC-2026-0596/",
  "https://plugins.svn.wordpress.org/robokassa/tags/1.9.0/",
  "https://wordpress.org/plugins/robokassa/"
 ],
 "attacksurface_url": "https://attacksurface.wpsec.com/plugin/robokassa",
 "source": "WPSec",
 "license": {
  "name": "CC BY 4.0",
  "url": "https://creativecommons.org/licenses/by/4.0/"
 },
 "usage": {
  "plugin": "Low",
  "affected_versions": "None seen",
  "as_of": "2026-10-07"
 }
}