WordPress Plugin Vulnerabilities

Wallet System for WooCommerce 2.0.0 - 2.7.10 - Subscriber+ Forged Wallet Withdrawal Request via IDOR

Description

The plugin does not verify that the wallet account named in a withdrawal submission belongs to the user making it, allowing any authenticated user, such as a subscriber, to file a withdrawal request against another user's wallet for an amount and a payout destination of their choosing, and to indefinitely prevent that user from submitting withdrawals of their own.

Proof of Concept

Affects Plugins

References

Classification

Type
IDOR
CWE

Miscellaneous

Original Researcher
Mytears
Submitter
Mytears
Verified
Yes

Timeline

Publicly Published
2026-10-06 (about 2 days ago)
Added
2026-10-06 (about 1 day ago)
Last Updated
2026-10-06 (about 1 day ago)

Other