Impact
The vulnerability arises because the plugin fails to verify that the wallet being debited belongs to the authenticated user initiating the transfer. This flaw permits any logged–in user, even those with only a Subscriber role, to move the balance of any other user—including administrators—into an account they control. The result is that an attacker can steal arbitrary amounts of virtual currency or store credit, leading to significant financial loss and undermining the integrity of the e‑commerce platform.
Affected Systems
Any WordPress site running the Wallet System for WooCommerce plugin with a version older than 2.8.0 is impacted. This includes all releases from 2.0.0 up to and including 2.7.10. The specific vendor is not named, but the plugin provides wallet management functionality for WooCommerce stores.
Risk and Exploitability
The flaw can be exploited by any authenticated user; no special privileges are required beyond a login. Because the plugin does not enforce ownership checks, the attacker can easily initiate a wallet transfer from any target. Exploit probability cannot be quantified due to an unavailable EPSS score, but the decisiveness of the authorization bypass suggests a high exploitation potential. The vulnerability is not listed in CISA’s KEV catalog, yet the financial impact and ease of attack warrant serious attention.
OpenCVE Enrichment