Wallet for WooCommerce <= 1.7.1 - Unauthenticated Business Logic Flaw to Unlimited Wallet Credit via Visit Referral Rewards
- ID
- WPSEC-2026-0683
- Plugin
- Wallet for WooCommerce (woo-wallet)
- Affected
- from 1.3.5 before 1.7.2
- Remediation
- Update to 1.7.2 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
- Weakness
- CWE-837
- Usage
- Plugin Medium · Affected versions Medium among sites WPSec scans, 2026-10-08
- Attack surface
- Wallet for WooCommerce on WPSec AttackSurface
- Fix released
- Published
Description
The Wallet for WooCommerce plugin for WordPress is vulnerable to a business logic flaw in the visit referral reward feature in versions 1.3.5 up to, and including, 1.7.1. The plugin credited the referrer's wallet for visits by logged-out visitors and relied only on a browser cookie to prevent repeat rewards, because its database check applied only to logged-in visitors. This makes it possible for unauthenticated attackers to repeatedly credit store credit to any user's wallet, including their own, when referral rewards are enabled. The credit is unlimited unless the site sets a per-period reward limit, which is not set by default.
References
- https://wpsec.com/vuln/WPSEC-2026-0683/
- https://plugins.svn.wordpress.org/woo-wallet/tags/1.7.2/
- https://wordpress.org/plugins/woo-wallet/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS