Vulnerabilities / Wallet System for WooCommerce / WPSEC-2026-0567
Wallet System for WooCommerce <= 2.7.10 - Unauthenticated Sensitive Information Exposure via Publicly Accessible Transaction CSV Export File
Low 3.7
CWE-552Fixed in 2.8.0
- ID
- WPSEC-2026-0567
- Plugin
- Wallet System for WooCommerce – Digital Wallet, Buy Now Pay Later (BNPL), Instant Cashback, Referral program, Partial & Subscription Payments (wallet-system-for-woocommerce)
- Affected
- from 2.5.6 before 2.8.0
- Remediation
- Update to 2.8.0 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
- Weakness
- CWE-552
- Usage
- Plugin Low · Affected versions Low among sites WPSec scans, 2026-10-07
- Attack surface
- Wallet System for WooCommerce on WPSec AttackSurface
- Fix released
- Published
Description
The Wallet System for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in versions 2.5.6 up to, and including, 2.7.10 because the transaction CSV export writes every user's wallet transactions to a file with a fixed name in a web-accessible directory (typically wp-admin/), where it remains after the export instead of being streamed to the requester. This makes it possible for unauthenticated attackers to download the file and obtain users' names, email addresses and transaction details once a CSV export has been generated.
References
- https://wpsec.com/vuln/WPSEC-2026-0567/
- https://plugins.svn.wordpress.org/wallet-system-for-woocommerce/tags/2.8.0/
- https://wordpress.org/plugins/wallet-system-for-woocommerce/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS