# Robokassa payment gateway for Woocommerce <= 1.8.9 - Unauthenticated Insecure Direct Object Reference to Order Key Exposure via 'InvId' Parameter

- **ID:** WPSEC-2026-0596
- **Plugin:** Robokassa payment gateway for Woocommerce (`robokassa`), https://wordpress.org/plugins/robokassa/
- **Affected versions:** all versions before 1.9.0
- **Fixed in:** 1.9.0 (Update to 1.9.0 or later.)
- **Severity:** Low 3.7 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N)
- **Weakness:** CWE-639
- **Usage among sites WPSec scans:** plugin Low, affected versions None seen (as of 2026-10-07)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/robokassa
- **Fix released:** 2026-10-05
- **Published:** 2026-10-07
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0596/

## Description

The Robokassa payment gateway for Woocommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.8.9 via the payment success and fail redirect endpoints, which build an order-specific redirect URL from the unsigned, user-supplied 'InvId' parameter. This makes it possible for unauthenticated attackers to obtain the order-received URL, including the order key, of arbitrary orders and, where WooCommerce does not require further verification, view those orders' details.

## References

- https://wpsec.com/vuln/WPSEC-2026-0596/
- https://plugins.svn.wordpress.org/robokassa/tags/1.9.0/
- https://wordpress.org/plugins/robokassa/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0596/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
