CVE-2026-65434 MEDIUM

CVE-2026-65434: WordPress ЮKassa для WooCommerce plugin <= 2.16.1 - Sensitive Data Exposure vulnerability

Vendor Yoomoney
Product ЮKassa для WooCommerce
Weakness CWE-201
Published July 27, 2026
Last update July 27, 2026

CVSS base score

6.5/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality High
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

What the vulnerability does

01Description

Subscriber Sensitive Data Exposure in ЮKassa для WooCommerce <= 2.16.1 versions.

Explanation of Vulnerability in Simple Terms

02Summary

The YooMoney payment gateway plugin for WooCommerce (versions up to 2.16.1) exposes sensitive payment and customer data to authenticated users with low privileges. An attacker with a standard user account can read confidential information including transaction details and personal data. The vulnerability does not allow modification or deletion of data, but the information disclosure poses a significant privacy risk for site operators and their customers.

What an attacker can do

03Attacker Capabilities

Read sensitive payment transaction data and customer information accessible through the plugin.

Potential impact on your site

04Site Impact

Customer payment records and personal data may be exposed to unauthorized users with basic site access.

Conditions required to exploit

05Prerequisites

Attacker must have a low-privilege user account on the WooCommerce site; no user interaction required.

Key dates

06Disclosure timeline

July 27, 2026 CVE published
July 27, 2026 Record updated

Related vulnerabilities

08Related CVE