# Wallet for WooCommerce <= 1.7.1 - Unauthenticated Business Logic Flaw to Unlimited Wallet Credit via Visit Referral Rewards

- **ID:** WPSEC-2026-0683
- **Plugin:** Wallet for WooCommerce (`woo-wallet`), https://wordpress.org/plugins/woo-wallet/
- **Affected versions:** from 1.3.5 before 1.7.2
- **Fixed in:** 1.7.2 (Update to 1.7.2 or later.)
- **Severity:** Medium 5.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
- **Weakness:** CWE-837
- **Usage among sites WPSec scans:** plugin Medium, affected versions Medium (as of 2026-10-08)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/woo-wallet
- **Fix released:** 2026-10-08
- **Published:** 2026-10-09
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0683/

## Description

The Wallet for WooCommerce plugin for WordPress is vulnerable to a business logic flaw in the visit referral reward feature in versions 1.3.5 up to, and including, 1.7.1. The plugin credited the referrer's wallet for visits by logged-out visitors and relied only on a browser cookie to prevent repeat rewards, because its database check applied only to logged-in visitors. This makes it possible for unauthenticated attackers to repeatedly credit store credit to any user's wallet, including their own, when referral rewards are enabled. The credit is unlimited unless the site sets a per-period reward limit, which is not set by default.

## References

- https://wpsec.com/vuln/WPSEC-2026-0683/
- https://plugins.svn.wordpress.org/woo-wallet/tags/1.7.2/
- https://wordpress.org/plugins/woo-wallet/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0683/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
