Description
The Wallet System for WooCommerce WordPress plugin before 2.8.0 does not verify that the user submitting a wallet transfer owns the wallet being debited, allowing any authenticated user, including one with only the Subscriber role, to move an arbitrary user's wallet balance, including an administrator's, into an account they control.
Published: 2026-10-08
Score: n/a
EPSS: n/a
KEV: No
Impact: Unauthorized transfer of wallet balance
Action: Immediate Patch
AI Analysis

Impact

The vulnerability arises because the plugin fails to verify that the wallet being debited belongs to the authenticated user initiating the transfer. This flaw permits any logged–in user, even those with only a Subscriber role, to move the balance of any other user—including administrators—into an account they control. The result is that an attacker can steal arbitrary amounts of virtual currency or store credit, leading to significant financial loss and undermining the integrity of the e‑commerce platform.

Affected Systems

Any WordPress site running the Wallet System for WooCommerce plugin with a version older than 2.8.0 is impacted. This includes all releases from 2.0.0 up to and including 2.7.10. The specific vendor is not named, but the plugin provides wallet management functionality for WooCommerce stores.

Risk and Exploitability

The flaw can be exploited by any authenticated user; no special privileges are required beyond a login. Because the plugin does not enforce ownership checks, the attacker can easily initiate a wallet transfer from any target. Exploit probability cannot be quantified due to an unavailable EPSS score, but the decisiveness of the authorization bypass suggests a high exploitation potential. The vulnerability is not listed in CISA’s KEV catalog, yet the financial impact and ease of attack warrant serious attention.

Generated by OpenCVE AI on October 8, 2026 at 07:37 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Wallet System for WooCommerce plugin to version 2.8.0 or later, where the ownership validation on wallet transfers has been fixed.
  • If an immediate upgrade is not possible, restrict the transfer capability to users with elevated roles (e.g., Administrators) or disable the transfer function entirely until a patch is applied.
  • Implement additional server‑side checks that compare the wallet ID submitted by the user with the wallet ID belonging to the authenticated user before performing any debit operation.
  • Conduct a security review of all wallet‑related endpoints to ensure that proper access controls and input validation are in place, mitigating the risk of similar IDOR issues in other components.

Generated by OpenCVE AI on October 8, 2026 at 07:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 08:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-639

Thu, 08 Oct 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Wallet System for WooCommerce WordPress plugin before 2.8.0 does not verify that the user submitting a wallet transfer owns the wallet being debited, allowing any authenticated user, including one with only the Subscriber role, to move an arbitrary user's wallet balance, including an administrator's, into an account they control.
Title Wallet System for WooCommerce 2.0.0 - 2.7.10 - Subscriber+ Arbitrary Wallet Balance Theft via IDOR
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-10-08T06:00:08.875Z

Reserved: 2026-09-21T08:22:15.602Z

Link: CVE-2026-94245

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-08T06:16:46.533

Modified: 2026-10-08T06:16:46.533

Link: CVE-2026-94245

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T07:45:17Z

Weaknesses
  • CWE-284

    Improper Access Control

  • CWE-639

    Authorization Bypass Through User-Controlled Key