Impact
The Wallet System for WooCommerce plugin, in all releases prior to 2.8.0, performs no capability check when generating a wallet transaction report. An authentication token that can be obtained from a public front‑end page is enough to trigger the export of every customer’s wallet history, including names, email addresses, roles, amounts, payment methods and transaction dates. This flaw is an example of improper access control that results in an information disclosure vulnerability.
Affected Systems
WordPress sites that install the Wallet System for WooCommerce plugin with a version earlier than 2.8.0. Any authenticated user with a valid session – such as a subscriber – can trigger the data export and receive a complete record of all users’ wallet transactions.
Risk and Exploitability
The vulnerability can be exercised by any logged‑in user, as the attacker only needs to craft a request to the export endpoint. Because the flaw is remote and requires no special privileges beyond authentication, the likelihood of exploitation is high in environments that lack role restrictions. No EPSS value is published, but the absence of a capability check imposes a significant confidentiality risk. The vulnerability is not listed in CISA’s KEV catalog. An attacker who obtains the export data could resume user profiles or conduct targeted phishing or financial fraud.
OpenCVE Enrichment