plugin

Yookassa Vulnerabilities

4 known security issues reported for the Yookassa WordPress plugin. Most recent disclosed Jul 27, 2026.

1 high 3 medium

Running Yookassa on your site? Check whether your installed version is affected.

Scan your site free

ЮKassa для WooCommerce <= 2.16.1 - Authenticated (Subscriber+) Information Exposure

medium

The ЮKassa для WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 2.16.1. This makes it possible for authenticated attackers, with subscriber-level access and above, to extract sensitive user or configuration data.

CVSS:
4.3
Affected:
up to 2.16.1
Fixed in:
2.16.2
Disclosed:
Jul 27, 2026

CVE-2026-65434 on NVD →

ЮKassa для WooCommerce <= 2.16.1 - Missing Authorization

medium

The ЮKassa для WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 2.16.1. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.

CVSS:
4.3
Affected:
up to 2.16.1
Fixed in:
2.16.2
Disclosed:
Jul 22, 2026

CVE-2026-65457 on NVD →

ЮKassa для WooCommerce <= 2.3.0 - Cross-Site Request Forgery to Settings Update

high

The ЮKassa для WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.3.0. This is due to missing nonce validation on the save_settings() function found in the ~/admin/YooKassaAdmin.php file. This makes it possible for unauthenticated attackers to modify the plu...

CVSS:
8.8
Affected:
up to 2.3.0
Fixed in:
2.3.1
Disclosed:
Jul 29, 2022

CVE-2022-36379 on NVD →

ЮKassa для WooCommerce <= 2.3.0 - Missing Authorization

medium

The ЮKassa для WooCommerce plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the save_settings() function in versions up to, and including, 2.3.0. This makes it possible for authenticated attacker with minimal permissions, such as a subscriber, to update arbitrary settings...

CVSS:
5.4
Affected:
up to 2.3.0
Fixed in:
2.3.1
Disclosed:
Jul 29, 2022

CVE-2022-34868 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database