{
 "id": "WPSEC-2026-0570",
 "url": "https://wpsec.com/vuln/WPSEC-2026-0570/",
 "json_url": "https://wpsec.com/vuln/WPSEC-2026-0570/advisory.json",
 "markdown_url": "https://wpsec.com/vuln/WPSEC-2026-0570/index.md",
 "title": "Wallet System for WooCommerce <= 2.7.10 - Authenticated (Subscriber+) Insecure Direct Object Reference to Wallet Withdrawal Requests",
 "description": "The Wallet System for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in the wallet withdrawal request feature in versions 2.0.0 up to, and including, 2.7.10 due to the withdrawal handler trusting the user-supplied 'wallet_user_id' parameter and saving every submitted form field on the request. This makes it possible for authenticated attackers, with Subscriber-level access and above, to submit withdrawal requests against other users' wallets, which debit the victim's wallet if an administrator approves them, and to set the withdrawal fee recorded on their requests.",
 "plugin": {
  "slug": "wallet-system-for-woocommerce",
  "name": "Wallet System for WooCommerce",
  "full_name": "Wallet System for WooCommerce – Digital Wallet, Buy Now Pay Later (BNPL), Instant Cashback, Referral program, Partial & Subscription Payments",
  "wordpress_org": "https://wordpress.org/plugins/wallet-system-for-woocommerce/",
  "advisories_url": "https://wpsec.com/vuln/plugin/wallet-system-for-woocommerce/",
  "attacksurface": "https://attacksurface.wpsec.com/plugin/wallet-system-for-woocommerce"
 },
 "type": "AUTHBYPASS",
 "cwe": [
  "CWE-639"
 ],
 "cve": [],
 "cvss": {
  "version": "3.1",
  "score": 4.3,
  "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N",
  "severity": "Medium"
 },
 "affected": {
  "ranges": [
   {
    "from": "2.0.0",
    "from_inclusive": true,
    "to": "2.8.0",
    "to_inclusive": false
   }
  ],
  "text": [
   "from 2.0.0 before 2.8.0"
  ]
 },
 "introduced_in": "2.0.0",
 "fixed_in": "2.8.0",
 "remediation": "Update to 2.8.0 or later.",
 "fix_released": "2026-10-05T05:14:05+00:00",
 "published": "2026-10-07T15:58:04+00:00",
 "updated": "2026-10-07T15:31:02.633399+00:00",
 "also_published_as": null,
 "references": [
  "https://wpsec.com/vuln/WPSEC-2026-0570/",
  "https://plugins.svn.wordpress.org/wallet-system-for-woocommerce/tags/2.8.0/",
  "https://wordpress.org/plugins/wallet-system-for-woocommerce/"
 ],
 "attacksurface_url": "https://attacksurface.wpsec.com/plugin/wallet-system-for-woocommerce",
 "source": "WPSec",
 "license": {
  "name": "CC BY 4.0",
  "url": "https://creativecommons.org/licenses/by/4.0/"
 },
 "usage": {
  "plugin": "Low",
  "affected_versions": "Low",
  "as_of": "2026-10-07"
 }
}