# Wallet System for WooCommerce <= 2.7.10 - Authenticated (Subscriber+) Missing Authorization to Sensitive Information Exposure via Wallet Transaction Export

- **ID:** WPSEC-2026-0568
- **Plugin:** Wallet System for WooCommerce – Digital Wallet, Buy Now Pay Later (BNPL), Instant Cashback, Referral program, Partial & Subscription Payments (`wallet-system-for-woocommerce`), https://wordpress.org/plugins/wallet-system-for-woocommerce/
- **Affected versions:** from 2.2.8 before 2.8.0
- **Fixed in:** 2.8.0 (Update to 2.8.0 or later.)
- **Severity:** Medium 4.3 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N)
- **Weakness:** CWE-862
- **Usage among sites WPSec scans:** plugin Low, affected versions Low (as of 2026-10-07)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/wallet-system-for-woocommerce
- **Fix released:** 2026-10-05
- **Published:** 2026-10-07
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0568/

## Description

The Wallet System for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the wallet transaction export (PDF/CSV) handler in versions 2.2.8 up to, and including, 2.7.10. The handler runs on every request. Before version 2.5.10 it checked no nonce at all; from 2.5.10 it was protected only by a nonce created with the generic default action, which any logged-in user receives on the plugin's My Account wallet pages. This makes it possible for authenticated attackers, with Subscriber-level access and above, to export the wallet transactions of all users, including names, email addresses, roles and amounts.

## References

- https://wpsec.com/vuln/WPSEC-2026-0568/
- https://plugins.svn.wordpress.org/wallet-system-for-woocommerce/tags/2.8.0/
- https://wordpress.org/plugins/wallet-system-for-woocommerce/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0568/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
