CVE-2026-91017
LOW
NVD
CVSS Score
3.7
Severity
LOW
Published
Sep 17, 2026
Vendor
unknown
Description
The Robokassa payment gateway for Woocommerce WordPress plugin before 1.8.9 does not verify the authenticity of incoming payment notifications when its non-default deferred-payment feature is enabled, allowing unauthenticated attackers to forge a notification and mark arbitrary WooCommerce orders as paid or on-hold without payment or a valid signature.