Wallet for WooCommerce <= 1.7.2 - Authenticated (Subscriber+) Business Logic Flaw to Unpaid Wallet Credit via Cash on Delivery Top-Up

Medium 5.3 CWE-840Fixed in 1.7.3
ID
WPSEC-2026-0692
Plugin
Wallet for WooCommerce (woo-wallet)
Affected
all versions before 1.7.3
Remediation
Update to 1.7.3 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N
Weakness
CWE-840
Usage
Plugin Medium · Affected versions Medium among sites WPSec scans, 2026-10-10
Attack surface
Wallet for WooCommerce on WPSec AttackSurface
Fix released
Published

Description

The Wallet for WooCommerce plugin for WordPress is vulnerable to a business logic flaw via the wallet top-up feature in all versions up to, and including, 1.7.2, due to the plugin allowing every enabled payment gateway, including cash on delivery, for top-ups by default and crediting the top-up as soon as the order reaches the 'processing' status, which WooCommerce assigns to cash on delivery orders at checkout before any payment is received. This makes it possible for authenticated attackers, with subscriber/customer-level access and above, to obtain spendable wallet credit without paying and use it on other orders, provided cash on delivery is enabled on the store.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0