The Wallet System for WooCommerce plugin, versions 2.0.0 through 2.7.10, contains a vulnerability that allows any authenticated user, including those with only the Subscriber role, to transfer an arbitrary user's wallet balance into their own account. This is due to a lack of verification on the user submitting a wallet transfer. The issue can lead to unauthorized access and potential financial loss. Defe [truncated]
ReviewWallet System for WooCommerceCVE published 2026-10-08
The Wallet System for WooCommerce plugin before version 2.8.0 allows any authenticated user, including subscribers, to export and disclose all users' wallet transaction history. This includes sensitive information such as names, email addresses, roles, transaction amounts, payment methods, and dates. The vulnerability can lead to unauthorized disclosure of sensitive information, potentially resulting in t [truncated]