# Wallet System for WooCommerce <= 2.7.10 - Unauthenticated Sensitive Information Exposure via Publicly Accessible Transaction CSV Export File

- **ID:** WPSEC-2026-0567
- **Plugin:** Wallet System for WooCommerce – Digital Wallet, Buy Now Pay Later (BNPL), Instant Cashback, Referral program, Partial & Subscription Payments (`wallet-system-for-woocommerce`), https://wordpress.org/plugins/wallet-system-for-woocommerce/
- **Affected versions:** from 2.5.6 before 2.8.0
- **Fixed in:** 2.8.0 (Update to 2.8.0 or later.)
- **Severity:** Low 3.7 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N)
- **Weakness:** CWE-552
- **Usage among sites WPSec scans:** plugin Low, affected versions Low (as of 2026-10-07)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/wallet-system-for-woocommerce
- **Fix released:** 2026-10-05
- **Published:** 2026-10-07
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0567/

## Description

The Wallet System for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in versions 2.5.6 up to, and including, 2.7.10 because the transaction CSV export writes every user's wallet transactions to a file with a fixed name in a web-accessible directory (typically wp-admin/), where it remains after the export instead of being streamed to the requester. This makes it possible for unauthenticated attackers to download the file and obtain users' names, email addresses and transaction details once a CSV export has been generated.

## References

- https://wpsec.com/vuln/WPSEC-2026-0567/
- https://plugins.svn.wordpress.org/wallet-system-for-woocommerce/tags/2.8.0/
- https://wordpress.org/plugins/wallet-system-for-woocommerce/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0567/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
