Wallet System for WooCommerce <= 2.7.10 - Authenticated (Subscriber+) Missing Authorization to Sensitive Information Exposure via Wallet Transaction Export

Medium 4.3 CWE-862Fixed in 2.8.0
ID
WPSEC-2026-0568
Plugin
Wallet System for WooCommerce – Digital Wallet, Buy Now Pay Later (BNPL), Instant Cashback, Referral program, Partial & Subscription Payments (wallet-system-for-woocommerce)
Affected
from 2.2.8 before 2.8.0
Remediation
Update to 2.8.0 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Weakness
CWE-862
Usage
Plugin Low · Affected versions Low among sites WPSec scans, 2026-10-07
Attack surface
Wallet System for WooCommerce on WPSec AttackSurface
Fix released
Published

Description

The Wallet System for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the wallet transaction export (PDF/CSV) handler in versions 2.2.8 up to, and including, 2.7.10. The handler runs on every request. Before version 2.5.10 it checked no nonce at all; from 2.5.10 it was protected only by a nonce created with the generic default action, which any logged-in user receives on the plugin's My Account wallet pages. This makes it possible for authenticated attackers, with Subscriber-level access and above, to export the wallet transactions of all users, including names, email addresses, roles and amounts.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0