PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-94245 Wallet System for WooCommerce CVE debrief

The Wallet System for WooCommerce plugin, versions 2.0.0 through 2.7.10, contains a vulnerability that allows any authenticated user, including those with only the Subscriber role, to transfer an arbitrary user's wallet balance into their own account. This is due to a lack of verification on the user submitting a wallet transfer. The issue can lead to unauthorized access and potential financial loss. Defenders responsible for maintaining WordPress installations with the Wallet System for WooCommerce plugin should assess exposure and prioritize updating to version 2.8.0 or later. This vulnerability has a significant impact as it allows low-privileged users to manipulate wallet and

Vendor
Wallet System for WooCommerce
Product
Wallet System for WooCommerce
CVSS
Unknown
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-08
Original CVE updated
2026-10-08
Advisory published
2026-10-08
Advisory updated
2026-10-08

Who should care

Defenders responsible for maintaining WordPress installations with the Wallet System for WooCommerce plugin should assess exposure and prioritize updating to version 2.8.0 or later.

Why it matters

Defenders should care about CVE-2026-94245 because it allows authenticated users to transfer arbitrary wallet balances, potentially leading to unauthorized access and financial loss. Defenders responsible for WordPress installations with the Wallet System for WooCommerce plugin should assess exposure and prioritize updating to version 2.8.0 or later.

  • Potential unauthorized wallet balance transfers
  • Possible exploitation by authenticated users with Subscriber role

Technical summary

The Wallet System for WooCommerce plugin before version 2.8.0 does not verify that the user submitting a wallet transfer owns the wallet being debited, allowing any authenticated user, including one with only the Subscriber role, to move an arbitrary user's wallet balance, including an administrator's, into an account they control. The vulnerability affects versions 2.0.0 through 2.7.10 of the plugin and allows for potential unauthorized access and financial loss. Defenders should prioritize updating to version 2.8.0 or later to prevent unauthorized wallet balance transfers.

Defensive priority

Defenders should prioritize updating to version 2.8.0 or later of the Wallet System for WooCommerce plugin to prevent unauthorized wallet balance transfers.

Recommended defensive actions

  • Update to version 2.8.0 or later of the Wallet System for WooCommerce plugin
  • Restrict access to sensitive wallet balance transfer functionality
  • Monitor for suspicious wallet balance transfers
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record and source item provide details on the vulnerability, including its description and affected versions. However, additional information from other sources may be necessary to fully assess the vulnerability.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-94245 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-94245

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-94245 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-94245

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.