WordPress Plugin Vulnerabilities

Robokassa payment gateway for Woocommerce < 1.8.9 - Unauthenticated Payment Bypass via Forged JWT Callback

Description

The plugin does not verify the authenticity of incoming payment notifications when its non-default deferred-payment feature is enabled, allowing unauthenticated attackers to forge a notification and mark arbitrary WooCommerce orders as paid or on-hold without payment or a valid signature.

Proof of Concept

Affects Plugins

Fixed in 1.8.9

References

Miscellaneous

Original Researcher
Pedro Pinho
Submitter
Pedro Pinho
Verified
Yes

Timeline

Publicly Published
2026-09-15 (about 22 days ago)
Added
2026-09-15 (about 21 days ago)
Last Updated
2026-09-15 (about 21 days ago)

Other