Impact
The Wallet System for WooCommerce plugin, before version 2.8.0, lacks a check to verify that the wallet account named in a withdrawal request belongs to the user making the request. This allows any authenticated user, such as a subscriber or other non‑admin role, to submit a withdrawal on behalf of another user, specifying arbitrary payout amounts and destinations, and to block the victim from making legitimate withdrawals.
Affected Systems
The vulnerability affects the Wallet System for WooCommerce WordPress plugin versions 2.0.0 through 2.7.10. Users employing any of these versions are at risk if the plugin is active.
Risk and Exploitability
Because the flaw only requires a logged‑in user, it can be exploited by any authenticated member of the site. The lack of a CVSS score in the data implies that severity has not been formally quantified, but the ability to drain funds and deny service to other users signifies a high‑risk impact. The EPSS score is unavailable and the vulnerability is not listed in CISA KEV, so the probability of a public exploit is unknown but could be high in environments where the plugin is installed and widely used. The likely attack vector is a web‑based request that manipulates the wallet ID field, making the IDOR straightforward to execute from the victim’s own account.
OpenCVE Enrichment