PatchSiren

Wallet System for WooCommerce CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

Review Wallet System for WooCommerce CVE published 2026-10-08

CVE-2026-94245

The Wallet System for WooCommerce plugin, versions 2.0.0 through 2.7.10, contains a vulnerability that allows any authenticated user, including those with only the Subscriber role, to transfer an arbitrary user's wallet balance into their own account. This is due to a lack of verification on the user submitting a wallet transfer. The issue can lead to unauthorized access and potential financial loss. Defe [truncated]

Review Wallet System for WooCommerce CVE published 2026-10-08

CVE-2026-94244

The Wallet System for WooCommerce plugin before version 2.8.0 allows any authenticated user, including subscribers, to export and disclose all users' wallet transaction history. This includes sensitive information such as names, email addresses, roles, transaction amounts, payment methods, and dates. The vulnerability can lead to unauthorized disclosure of sensitive information, potentially resulting in t [truncated]