Wallet System for WooCommerce <= 2.7.10 - Authenticated (Subscriber+) Missing Authorization to Sensitive Information Exposure via Wallet Transaction Export
- ID
- WPSEC-2026-0568
- Plugin
- Wallet System for WooCommerce – Digital Wallet, Buy Now Pay Later (BNPL), Instant Cashback, Referral program, Partial & Subscription Payments (wallet-system-for-woocommerce)
- Affected
- from 2.2.8 before 2.8.0
- Remediation
- Update to 2.8.0 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- Weakness
- CWE-862
- Usage
- Plugin Low · Affected versions Low among sites WPSec scans, 2026-10-07
- Attack surface
- Wallet System for WooCommerce on WPSec AttackSurface
- Fix released
- Published
Description
The Wallet System for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the wallet transaction export (PDF/CSV) handler in versions 2.2.8 up to, and including, 2.7.10. The handler runs on every request. Before version 2.5.10 it checked no nonce at all; from 2.5.10 it was protected only by a nonce created with the generic default action, which any logged-in user receives on the plugin's My Account wallet pages. This makes it possible for authenticated attackers, with Subscriber-level access and above, to export the wallet transactions of all users, including names, email addresses, roles and amounts.
References
- https://wpsec.com/vuln/WPSEC-2026-0568/
- https://plugins.svn.wordpress.org/wallet-system-for-woocommerce/tags/2.8.0/
- https://wordpress.org/plugins/wallet-system-for-woocommerce/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS