Vulnerabilities / Wallet System for WooCommerce / WPSEC-2026-0566
Wallet System for WooCommerce <= 2.7.10 - Authenticated (Subscriber+) Wallet Balance Manipulation via Negative Transfer Amount
Medium 6.5
CWE-1284Fixed in 2.8.0
- ID
- WPSEC-2026-0566
- Plugin
- Wallet System for WooCommerce – Digital Wallet, Buy Now Pay Later (BNPL), Instant Cashback, Referral program, Partial & Subscription Payments (wallet-system-for-woocommerce)
- Affected
- from 2.0.0 before 2.8.0
- Remediation
- Update to 2.8.0 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
- Weakness
- CWE-1284
- Usage
- Plugin Low · Affected versions Low among sites WPSec scans, 2026-10-07
- Attack surface
- Wallet System for WooCommerce on WPSec AttackSurface
- Fix released
- Published
Description
The Wallet System for WooCommerce plugin for WordPress is vulnerable to unauthorized wallet balance manipulation in versions 2.0.0 up to, and including, 2.7.10 due to the wallet transfer feature accepting negative transfer amounts and relying on a user-supplied email address to prevent transfers to oneself. This makes it possible for authenticated attackers, with Subscriber-level access and above, to increase their own wallet balance or drain other users' wallets, and spend the balance at the store.
References
- https://wpsec.com/vuln/WPSEC-2026-0566/
- https://plugins.svn.wordpress.org/wallet-system-for-woocommerce/tags/2.8.0/
- https://wordpress.org/plugins/wallet-system-for-woocommerce/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS