Wallet System for WooCommerce <= 2.7.10 - Authenticated (Subscriber+) Wallet Balance Manipulation via Negative Transfer Amount

Medium 6.5 CWE-1284Fixed in 2.8.0
ID
WPSEC-2026-0566
Plugin
Wallet System for WooCommerce – Digital Wallet, Buy Now Pay Later (BNPL), Instant Cashback, Referral program, Partial & Subscription Payments (wallet-system-for-woocommerce)
Affected
from 2.0.0 before 2.8.0
Remediation
Update to 2.8.0 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Weakness
CWE-1284
Usage
Plugin Low · Affected versions Low among sites WPSec scans, 2026-10-07
Attack surface
Wallet System for WooCommerce on WPSec AttackSurface
Fix released
Published

Description

The Wallet System for WooCommerce plugin for WordPress is vulnerable to unauthorized wallet balance manipulation in versions 2.0.0 up to, and including, 2.7.10 due to the wallet transfer feature accepting negative transfer amounts and relying on a user-supplied email address to prevent transfers to oneself. This makes it possible for authenticated attackers, with Subscriber-level access and above, to increase their own wallet balance or drain other users' wallets, and spend the balance at the store.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0