CVE-2026-65457 MEDIUM

CVE-2026-65457: WordPress ЮKassa для WooCommerce plugin <= 2.16.1 - Broken Access Control vulnerability

Vendor Yoomoney
Product ЮKassa для WooCommerce
Weakness CWE-862 · Missing authorization
Published July 23, 2026
Last update July 23, 2026

CVSS base score

4.3/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality None
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

What the vulnerability does

01Description

Subscriber Broken Access Control in ЮKassa для WooCommerce <= 2.16.1 versions.

Explanation of Vulnerability in Simple Terms

02Summary

The YooMoney payment gateway plugin for WooCommerce versions up to 2.16.1 lacks proper authorization checks on certain functions. A logged-in user with low privileges can modify payment settings or transaction data without proper permission verification. This affects the integrity of payment processing but does not expose sensitive data or disrupt site availability.

What an attacker can do

03Attacker Capabilities

A logged-in user can modify payment settings or transaction records without proper authorization.

Potential impact on your site

04Site Impact

Unauthorized users may alter payment configuration or transaction details, potentially disrupting payment processing or creating fraudulent records.

Conditions required to exploit

05Prerequisites

Attacker must have a low-privilege account on the WooCommerce site (e.g., customer or subscriber role).

Key dates

06Disclosure timeline

July 23, 2026 CVE published