Impact
The Wallet for WooCommerce WordPress plugin before version 1.6.10 fails to verify the actual amount collected for a top‑up before adding the funds to the user’s wallet, allowing an attacker to submit a top‑up request for an arbitrary value while paying a lesser amount. This flaw can be exploited to inflate the wallet with no corresponding revenue, directly impacting the merchant’s finances. The weakness is a failure to validate transaction amounts before crediting the user account (CWE‑640) and an unauthorized ability to invoke top‑up functions (CWE‑284).
Affected Systems
Any WordPress site that has installed the Wallet for WooCommerce plugin with a version earlier than 1.6.10 is affected. The vulnerable component is the top‑up handling functionality within the plugin that interacts with the payment gateway. No further vendor version narrowing is provided.
Risk and Exploitability
The EPSS score is < 1%, and the vulnerability is not listed in the CISA KEV catalogue. The CVSS score of 9.1 indicates high severity. The vulnerability allows an attacker to generate arbitrary wallet credits with little or no financial outlay, which can lead to significant revenue loss and erosion of customer trust. The likely attack vector is exploitation of the site's top‑up feature or API endpoint, which is typically accessible via front‑end requests or payment‑gateway callbacks, providing a straightforward path for abuse.
OpenCVE Enrichment