# Wallet System for WooCommerce <= 2.7.10 - Authenticated (Subscriber+) Wallet Balance Manipulation via Negative Transfer Amount

- **ID:** WPSEC-2026-0566
- **Plugin:** Wallet System for WooCommerce – Digital Wallet, Buy Now Pay Later (BNPL), Instant Cashback, Referral program, Partial & Subscription Payments (`wallet-system-for-woocommerce`), https://wordpress.org/plugins/wallet-system-for-woocommerce/
- **Affected versions:** from 2.0.0 before 2.8.0
- **Fixed in:** 2.8.0 (Update to 2.8.0 or later.)
- **Severity:** Medium 6.5 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N)
- **Weakness:** CWE-1284
- **Usage among sites WPSec scans:** plugin Low, affected versions Low (as of 2026-10-07)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/wallet-system-for-woocommerce
- **Fix released:** 2026-10-05
- **Published:** 2026-10-07
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0566/

## Description

The Wallet System for WooCommerce plugin for WordPress is vulnerable to unauthorized wallet balance manipulation in versions 2.0.0 up to, and including, 2.7.10 due to the wallet transfer feature accepting negative transfer amounts and relying on a user-supplied email address to prevent transfers to oneself. This makes it possible for authenticated attackers, with Subscriber-level access and above, to increase their own wallet balance or drain other users' wallets, and spend the balance at the store.

## References

- https://wpsec.com/vuln/WPSEC-2026-0566/
- https://plugins.svn.wordpress.org/wallet-system-for-woocommerce/tags/2.8.0/
- https://wordpress.org/plugins/wallet-system-for-woocommerce/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0566/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
