Wallet System for WooCommerce <= 2.7.10 - Unauthenticated Sensitive Information Exposure via Publicly Accessible Transaction CSV Export File

Low 3.7 CWE-552Fixed in 2.8.0
ID
WPSEC-2026-0567
Plugin
Wallet System for WooCommerce – Digital Wallet, Buy Now Pay Later (BNPL), Instant Cashback, Referral program, Partial & Subscription Payments (wallet-system-for-woocommerce)
Affected
from 2.5.6 before 2.8.0
Remediation
Update to 2.8.0 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Weakness
CWE-552
Usage
Plugin Low · Affected versions Low among sites WPSec scans, 2026-10-07
Attack surface
Wallet System for WooCommerce on WPSec AttackSurface
Fix released
Published

Description

The Wallet System for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in versions 2.5.6 up to, and including, 2.7.10 because the transaction CSV export writes every user's wallet transactions to a file with a fixed name in a web-accessible directory (typically wp-admin/), where it remains after the export instead of being streamed to the requester. This makes it possible for unauthenticated attackers to download the file and obtain users' names, email addresses and transaction details once a CSV export has been generated.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0