Impact
The Wallet for WooCommerce WordPress plugin before version 1.6.10 fails to verify the actual amount collected for a top‑up before adding the funds to the user’s wallet, allowing an attacker to submit a top‑up request for an arbitrary value while paying a lesser amount. This flaw can be exploited to inflate the wallet with no corresponding revenue, directly impacting the merchant’s finances. The weakness is a failure to validate transaction amounts before crediting the user account (CWE‑640).
Affected Systems
Any WordPress site that has installed the Wallet for WooCommerce plugin with a version earlier than 1.6.10 is affected. The vulnerable component is the top‑up handling functionality within the plugin that interacts with the payment gateway. No further vendor version narrowing is provided.
Risk and Exploitability
No EPSS score is available for this vulnerability, and it is not listed in the CISA KEV catalogue. The CVSS score is not disclosed, so the absolute severity cannot be quantified. Nevertheless, because the flaw allows an attacker to generate arbitrary wallet credits with little or no financial outlay, the risk to the merchant’s revenue and potentially to customer trust is considerable. The likely attack vector is exploitation of the site's top‑up feature or API endpoint, which is typically accessible via front‑end requests or payment‑gateway callbacks, providing a straightforward path for abuse.
OpenCVE Enrichment