PatchSiren cyber security CVE debrief
CVE-2026-94245 Wallet System for WooCommerce CVE debrief
The Wallet System for WooCommerce plugin, versions 2.0.0 through 2.7.10, contains a vulnerability that allows any authenticated user, including those with only the Subscriber role, to transfer an arbitrary user's wallet balance into their own account. This is due to a lack of verification on the user submitting a wallet transfer. The issue can lead to unauthorized access and potential financial loss. Defenders responsible for maintaining WordPress installations with the Wallet System for WooCommerce plugin should assess exposure and prioritize updating to version 2.8.0 or later. This vulnerability has a significant impact as it allows low-privileged users to manipulate wallet and
- Vendor
- Wallet System for WooCommerce
- Product
- Wallet System for WooCommerce
- CVSS
- Unknown
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-08
- Original CVE updated
- 2026-10-08
- Advisory published
- 2026-10-08
- Advisory updated
- 2026-10-08
Who should care
Defenders responsible for maintaining WordPress installations with the Wallet System for WooCommerce plugin should assess exposure and prioritize updating to version 2.8.0 or later.
Why it matters
Defenders should care about CVE-2026-94245 because it allows authenticated users to transfer arbitrary wallet balances, potentially leading to unauthorized access and financial loss. Defenders responsible for WordPress installations with the Wallet System for WooCommerce plugin should assess exposure and prioritize updating to version 2.8.0 or later.
- Potential unauthorized wallet balance transfers
- Possible exploitation by authenticated users with Subscriber role
Technical summary
The Wallet System for WooCommerce plugin before version 2.8.0 does not verify that the user submitting a wallet transfer owns the wallet being debited, allowing any authenticated user, including one with only the Subscriber role, to move an arbitrary user's wallet balance, including an administrator's, into an account they control. The vulnerability affects versions 2.0.0 through 2.7.10 of the plugin and allows for potential unauthorized access and financial loss. Defenders should prioritize updating to version 2.8.0 or later to prevent unauthorized wallet balance transfers.
Defensive priority
Defenders should prioritize updating to version 2.8.0 or later of the Wallet System for WooCommerce plugin to prevent unauthorized wallet balance transfers.
Recommended defensive actions
- Update to version 2.8.0 or later of the Wallet System for WooCommerce plugin
- Restrict access to sensitive wallet balance transfer functionality
- Monitor for suspicious wallet balance transfers
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record and source item provide details on the vulnerability, including its description and affected versions. However, additional information from other sources may be necessary to fully assess the vulnerability.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-94245 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-94245
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-94245 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-94245
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Wallet System for WooCommerce 2.0.0 - 2.7.10 - Subscriber+ Arbitrary Wallet Balance Theft via ID
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/94xxx/CVE-2026-94245.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://wpscan.com/vulnerability/fd44c88d-2ca4-4e3d-9e9f-570e239df4bd/
Supplemental source - exploit, vdb-entry, technical-description
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.