{
 "id": "WPSEC-2026-0683",
 "url": "https://wpsec.com/vuln/WPSEC-2026-0683/",
 "json_url": "https://wpsec.com/vuln/WPSEC-2026-0683/advisory.json",
 "markdown_url": "https://wpsec.com/vuln/WPSEC-2026-0683/index.md",
 "title": "Wallet for WooCommerce <= 1.7.1 - Unauthenticated Business Logic Flaw to Unlimited Wallet Credit via Visit Referral Rewards",
 "description": "The Wallet for WooCommerce plugin for WordPress is vulnerable to a business logic flaw in the visit referral reward feature in versions 1.3.5 up to, and including, 1.7.1. The plugin credited the referrer's wallet for visits by logged-out visitors and relied only on a browser cookie to prevent repeat rewards, because its database check applied only to logged-in visitors. This makes it possible for unauthenticated attackers to repeatedly credit store credit to any user's wallet, including their own, when referral rewards are enabled. The credit is unlimited unless the site sets a per-period reward limit, which is not set by default.",
 "plugin": {
  "slug": "woo-wallet",
  "name": "Wallet for WooCommerce",
  "full_name": "Wallet for WooCommerce",
  "wordpress_org": "https://wordpress.org/plugins/woo-wallet/",
  "advisories_url": "https://wpsec.com/vuln/plugin/woo-wallet/",
  "attacksurface": "https://attacksurface.wpsec.com/plugin/woo-wallet"
 },
 "type": "UNKNOWN",
 "cwe": [
  "CWE-837"
 ],
 "cve": [],
 "cvss": {
  "version": "3.1",
  "score": 5.3,
  "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
  "severity": "Medium"
 },
 "affected": {
  "ranges": [
   {
    "from": "1.3.5",
    "from_inclusive": true,
    "to": "1.7.2",
    "to_inclusive": false
   }
  ],
  "text": [
   "from 1.3.5 before 1.7.2"
  ]
 },
 "introduced_in": "1.3.5",
 "fixed_in": "1.7.2",
 "remediation": "Update to 1.7.2 or later.",
 "fix_released": "2026-10-08T02:19:33+00:00",
 "published": "2026-10-09T02:40:44+00:00",
 "updated": "2026-10-08T07:40:26.735023+00:00",
 "also_published_as": null,
 "references": [
  "https://wpsec.com/vuln/WPSEC-2026-0683/",
  "https://plugins.svn.wordpress.org/woo-wallet/tags/1.7.2/",
  "https://wordpress.org/plugins/woo-wallet/"
 ],
 "attacksurface_url": "https://attacksurface.wpsec.com/plugin/woo-wallet",
 "source": "WPSec",
 "license": {
  "name": "CC BY 4.0",
  "url": "https://creativecommons.org/licenses/by/4.0/"
 },
 "usage": {
  "plugin": "Medium",
  "affected_versions": "Medium",
  "as_of": "2026-10-08"
 }
}