Wallet for WooCommerce <= 1.7.1 - Unauthenticated Business Logic Flaw to Unlimited Wallet Credit via Visit Referral Rewards

Medium 5.3 CWE-837Fixed in 1.7.2
ID
WPSEC-2026-0683
Plugin
Wallet for WooCommerce (woo-wallet)
Affected
from 1.3.5 before 1.7.2
Remediation
Update to 1.7.2 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Weakness
CWE-837
Usage
Plugin Medium · Affected versions Medium among sites WPSec scans, 2026-10-08
Attack surface
Wallet for WooCommerce on WPSec AttackSurface
Fix released
Published

Description

The Wallet for WooCommerce plugin for WordPress is vulnerable to a business logic flaw in the visit referral reward feature in versions 1.3.5 up to, and including, 1.7.1. The plugin credited the referrer's wallet for visits by logged-out visitors and relied only on a browser cookie to prevent repeat rewards, because its database check applied only to logged-in visitors. This makes it possible for unauthenticated attackers to repeatedly credit store credit to any user's wallet, including their own, when referral rewards are enabled. The credit is unlimited unless the site sets a per-period reward limit, which is not set by default.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0