SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-65457

MEDIUM · CVSS 4.3 EPSS 0.24%

Source: NVD + CISA KEV + EPSS · Published 2026-07-23 · Last synced 2026-08-22

CyberRota Analysis

AI-Generated

The vulnerability in ЮKassa для WooCommerce versions up to 2.16.1 allows for broken access control, potentially enabling unauthorized users to access restricted subscriber functionalities. This could lead to data exposure or manipulation, impacting the integrity of user transactions. E-commerce platforms utilizing this plugin should prioritize remediation to safeguard customer data and maintain compliance.

CVE
CVE-2026-65457
Severity
MEDIUM
CVSS
4.3
EPSS
0.24%

Original NVD Description

Subscriber Broken Access Control in ЮKassa для WooCommerce <= 2.16.1 versions.