WordPress Plugin Vulnerabilities
Wallet System for WooCommerce < 2.7.10 - Customer+ Checkout Price Manipulation via Unvalidated Wallet Amount
Description
The plugin does not validate a user-supplied wallet amount against the customer's actual stored balance during checkout, allowing authenticated customers to arbitrarily reduce their own order total, including down to zero, and complete checkout without paying the merchant.
Proof of Concept
Affects Plugins
References
CVE
Miscellaneous
Submitter
takuma
Verified
Yes
WPVDB ID
Timeline
Publicly Published
2026-08-10 (about 24 days ago)
Added
2026-08-10 (about 23 days ago)
Last Updated
2026-08-10 (about 23 days ago)