Description
The Wallet System for WooCommerce WordPress plugin before 2.8.0 does not perform any capability check, and relies on a token any authenticated user can obtain from a front-end page, before generating a report containing every customer's wallet transaction history, allowing any authenticated user, such as a subscriber, to disclose all users' names, email addresses, roles, transaction amounts, payment methods and dates.
Published: 2026-10-08
Score: n/a
EPSS: n/a
KEV: No
Impact: Exfiltration of sensitive user transaction data
Action: Immediate Patch
AI Analysis

Impact

The Wallet System for WooCommerce plugin, in all releases prior to 2.8.0, performs no capability check when generating a wallet transaction report. An authentication token that can be obtained from a public front‑end page is enough to trigger the export of every customer’s wallet history, including names, email addresses, roles, amounts, payment methods and transaction dates. This flaw is an example of improper access control that results in an information disclosure vulnerability.

Affected Systems

WordPress sites that install the Wallet System for WooCommerce plugin with a version earlier than 2.8.0. Any authenticated user with a valid session – such as a subscriber – can trigger the data export and receive a complete record of all users’ wallet transactions.

Risk and Exploitability

The vulnerability can be exercised by any logged‑in user, as the attacker only needs to craft a request to the export endpoint. Because the flaw is remote and requires no special privileges beyond authentication, the likelihood of exploitation is high in environments that lack role restrictions. No EPSS value is published, but the absence of a capability check imposes a significant confidentiality risk. The vulnerability is not listed in CISA’s KEV catalog. An attacker who obtains the export data could resume user profiles or conduct targeted phishing or financial fraud.

Generated by OpenCVE AI on October 8, 2026 at 07:38 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Wallet System for WooCommerce plugin to version 2.8.0 or later.
  • Restrict the export functionality to privileged roles such as administrators or shop managers, preventing subscribers from accessing it.
  • Audit access logs for repeated export attempts and enforce rate limiting or additional authentication checks on the export endpoint.

Generated by OpenCVE AI on October 8, 2026 at 07:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 08:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-284

Thu, 08 Oct 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Wallet System for WooCommerce WordPress plugin before 2.8.0 does not perform any capability check, and relies on a token any authenticated user can obtain from a front-end page, before generating a report containing every customer's wallet transaction history, allowing any authenticated user, such as a subscriber, to disclose all users' names, email addresses, roles, transaction amounts, payment methods and dates.
Title Wallet System for WooCommerce < 2.8.0 - Subscriber+ Store-Wide Wallet Transaction Disclosure via Export
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-10-08T06:00:08.698Z

Reserved: 2026-09-21T08:22:13.715Z

Link: CVE-2026-94244

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-08T06:16:46.197

Modified: 2026-10-08T06:16:46.197

Link: CVE-2026-94244

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T07:45:17Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-284

    Improper Access Control