ЮKassa для WooCommerce <= 2.16.1 - Authenticated (Subscriber+) Information Exposure
medium
The ЮKassa для WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 2.16.1. This makes it possible for authenticated attackers, with subscriber-level access and above, to extract sensitive user or configuration data.
- CVSS:
- 4.3
- Affected:
- up to 2.16.1
- Fixed in:
- 2.16.2
- Disclosed:
- Jul 27, 2026
CVE-2026-65434 on NVD →
ЮKassa для WooCommerce <= 2.16.1 - Missing Authorization
medium
The ЮKassa для WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 2.16.1. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.
- CVSS:
- 4.3
- Affected:
- up to 2.16.1
- Fixed in:
- 2.16.2
- Disclosed:
- Jul 22, 2026
CVE-2026-65457 on NVD →
ЮKassa для WooCommerce <= 2.3.0 - Cross-Site Request Forgery to Settings Update
high
The ЮKassa для WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.3.0. This is due to missing nonce validation on the save_settings() function found in the ~/admin/YooKassaAdmin.php file. This makes it possible for unauthenticated attackers to modify the plu...
- CVSS:
- 8.8
- Affected:
- up to 2.3.0
- Fixed in:
- 2.3.1
- Disclosed:
- Jul 29, 2022
CVE-2022-36379 on NVD →
ЮKassa для WooCommerce <= 2.3.0 - Missing Authorization
medium
The ЮKassa для WooCommerce plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the save_settings() function in versions up to, and including, 2.3.0. This makes it possible for authenticated attacker with minimal permissions, such as a subscriber, to update arbitrary settings...
- CVSS:
- 5.4
- Affected:
- up to 2.3.0
- Fixed in:
- 2.3.1
- Disclosed:
- Jul 29, 2022
CVE-2022-34868 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database