Description
The Wallet System for WooCommerce WordPress plugin before 2.8.0 does not validate that a wallet transfer amount is positive, and computes the sender's new balance from a stale snapshot taken before crediting the recipient, allowing an authenticated attacker with Subscriber-level access to mint wallet funds for themselves or drain a specific victim's balance into their own account.
Published: 2026-10-08
Score: 6.5 Medium
EPSS: n/a
KEV: No
Impact: Unauthorized creation or transfer of wallet funds
Action: Immediate patch
AI Analysis

Impact

The Wallet System for WooCommerce plugin before 2.8.0 does not enforce that a transfer amount is positive. An authenticated user with Subscriber‑level privileges can submit a negative value, causing the system to compute the sender’s new balance from a stale snapshot taken before crediting the recipient. This flaw allows the attacker to mint additional funds for themselves or to drain a victim’s wallet balance into their own account, thereby compromising the integrity of wallet balances. The weakness stems from improper input validation (CWE‑20). The impact is non‑remote code execution but results in financial manipulation within the platform.

Affected Systems

WordPress installations using the Wallet System for WooCommerce plugin versions 2.0.0 through 2.7.10 are affected. Any site that has not upgraded to 2.8.0 or later remains vulnerable. No other product versions are listed as affected.

Risk and Exploitability

The CVSS score of 6.5 indicates moderate severity. The EPSS score is not available, so the likelihood of exploitation is unclear but potentially high given the attacker only needs Subscriber‑level access. The vulnerability is not listed in CISA KEV, but its existence is publicly documented. The likely attack vector is authenticated exploitation within the WooCommerce environment, where an attacker manipulates the transfer amount to affect wallet balances. The lack of validation and the use of a stale snapshot provide a straightforward path for an attacker to inflate or reduce balances at will.

Generated by OpenCVE AI on October 8, 2026 at 11:20 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Wallet System for WooCommerce to version 2.8.0 or later.
  • Implement server‑side validation that rejects negative transfer amounts when no patch is available.
  • Review and restrict Subscriber‑level permissions to prevent unauthorized wallet transfers.

Generated by OpenCVE AI on October 8, 2026 at 11:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 11:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 08 Oct 2026 10:45:00 +0000

Type Values Removed Values Added
Description The Wallet System for WooCommerce WordPress plugin before 2.8.0 does not validate that a wallet transfer amount is positive, and computes the sender's new balance from a stale snapshot taken before crediting the recipient, allowing an authenticated attacker with Subscriber-level access to mint wallet funds for themselves or drain a specific victim's balance into their own account.
Title Wallet System for WooCommerce 2.0.0 - 2.7.10 - Subscriber+ Wallet Balance Manipulation via Negative Transfer Amount
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-10-08T10:59:16.926Z

Reserved: 2026-09-18T08:43:15.081Z

Link: CVE-2026-93509

cve-icon Vulnrichment

Updated: 2026-10-08T10:53:41.893Z

cve-icon NVD

Status : Received

Published: 2026-10-08T11:16:47.217

Modified: 2026-10-08T11:16:47.217

Link: CVE-2026-93509

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T11:30:17Z

Weaknesses

No weakness.