Wallet for WooCommerce <= 1.7.0 - Cross-Site Request Forgery to Wallet Partial Payment Refund

Medium 4.3 CWE-352Fixed in 1.7.1
ID
WPSEC-2026-0443
Plugin
Wallet for WooCommerce (woo-wallet)
Affected
from 1.2.6 before 1.7.1
Remediation
Update to 1.7.1 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Weakness
CWE-352
Usage
Plugin Medium · Affected versions Medium among sites WPSec scans, 2026-10-06
Attack surface
Wallet for WooCommerce on WPSec AttackSurface
Fix released
Published

Description

The Wallet for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions 1.2.6 to 1.7.0 due to missing nonce validation in the woo_wallet_refund_partial_payment AJAX action. This makes it possible for unauthenticated attackers to refund the wallet-paid portion of an order to the customer's wallet via a forged request, provided they can trick a site administrator or shop manager into performing an action such as clicking a link.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0