{
 "id": "WPSEC-2026-0692",
 "url": "https://wpsec.com/vuln/WPSEC-2026-0692/",
 "json_url": "https://wpsec.com/vuln/WPSEC-2026-0692/advisory.json",
 "markdown_url": "https://wpsec.com/vuln/WPSEC-2026-0692/index.md",
 "title": "Wallet for WooCommerce <= 1.7.2 - Authenticated (Subscriber+) Business Logic Flaw to Unpaid Wallet Credit via Cash on Delivery Top-Up",
 "description": "The Wallet for WooCommerce plugin for WordPress is vulnerable to a business logic flaw via the wallet top-up feature in all versions up to, and including, 1.7.2, due to the plugin allowing every enabled payment gateway, including cash on delivery, for top-ups by default and crediting the top-up as soon as the order reaches the 'processing' status, which WooCommerce assigns to cash on delivery orders at checkout before any payment is received. This makes it possible for authenticated attackers, with subscriber/customer-level access and above, to obtain spendable wallet credit without paying and use it on other orders, provided cash on delivery is enabled on the store.",
 "plugin": {
  "slug": "woo-wallet",
  "name": "Wallet for WooCommerce",
  "full_name": "Wallet for WooCommerce",
  "wordpress_org": "https://wordpress.org/plugins/woo-wallet/",
  "advisories_url": "https://wpsec.com/vuln/plugin/woo-wallet/",
  "attacksurface": "https://attacksurface.wpsec.com/plugin/woo-wallet"
 },
 "type": "UNKNOWN",
 "cwe": [
  "CWE-840"
 ],
 "cve": [],
 "cvss": {
  "version": "3.1",
  "score": 5.3,
  "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N",
  "severity": "Medium"
 },
 "affected": {
  "ranges": [
   {
    "from": null,
    "from_inclusive": true,
    "to": "1.7.3",
    "to_inclusive": false
   }
  ],
  "text": [
   "all versions before 1.7.3"
  ]
 },
 "introduced_in": null,
 "fixed_in": "1.7.3",
 "remediation": "Update to 1.7.3 or later.",
 "fix_released": "2026-10-09T07:01:14+00:00",
 "published": "2026-10-10T15:41:27+00:00",
 "updated": "2026-10-10T14:53:01.206861+00:00",
 "also_published_as": null,
 "references": [
  "https://wpsec.com/vuln/WPSEC-2026-0692/",
  "https://plugins.svn.wordpress.org/woo-wallet/tags/1.7.3/",
  "https://wordpress.org/plugins/woo-wallet/"
 ],
 "attacksurface_url": "https://attacksurface.wpsec.com/plugin/woo-wallet",
 "source": "WPSec",
 "license": {
  "name": "CC BY 4.0",
  "url": "https://creativecommons.org/licenses/by/4.0/"
 },
 "usage": {
  "plugin": "Medium",
  "affected_versions": "Medium",
  "as_of": "2026-10-10"
 }
}