CVE-2026-78536: WordPress Robokassa payment gateway for Woocommerce plugin <= 1.8.9 - Broken Access Control vulnerability
Published Sep 10, 2026
·Updated
Unauthenticated Broken Access Control in Robokassa payment gateway for Woocommerce <= 1.8.9 versions.
Affected Software
1 affected component
WordPress Robokassa payment gateway for Woocommerce plugin<=1.8.9
Event History
Sep 10, 2026
CVE Published
via MITRE·02:23 PM
Data Sourced
via MITRE·02:23 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
The vulnerability is unauthenticated, so an attacker does not need a WordPress account or other prior privileges to exploit it.
2
What impact is indicated by the severity vector?
The vector indicates network-reachable exploitation with low attack complexity and no user interaction. It indicates low impact to integrity and availability, with no confidentiality impact.
3
Which plugin versions are affected?
Versions 1.8.9 and earlier of the Robokassa payment gateway for Woocommerce plugin are identified as affected.