Wallet for WooCommerce <= 1.7.0 - Authenticated (Vendor+) Incorrect Authorization to Wallet Partial Payment Refund

Low 3.1 CWE-863Fixed in 1.7.1
ID
WPSEC-2026-0444
Plugin
Wallet for WooCommerce (woo-wallet)
Affected
from 1.2.6 before 1.7.1
Remediation
Update to 1.7.1 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N
Weakness
CWE-863
Usage
Plugin Medium · Affected versions Medium among sites WPSec scans, 2026-10-06
Attack surface
Wallet for WooCommerce on WPSec AttackSurface
Fix released
Published

Description

The Wallet for WooCommerce plugin for WordPress is vulnerable to unauthorized wallet refunds in versions 1.2.6 to 1.7.0 due to the woo_wallet_refund_partial_payment AJAX action checking only for the edit_shop_orders capability, which marketplace plugins such as Dokan grant to every vendor for all orders. This makes it possible for authenticated attackers with vendor-level access on such marketplace sites to refund the wallet-paid portion of orders they do not own back to the ordering customer's wallet.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0