WordPress Plugin Vulnerabilities

Wallet System for WooCommerce 2.0.0 - 2.7.10 - Subscriber+ Arbitrary Wallet Balance Theft via IDOR

Description

The plugin does not verify that the user submitting a wallet transfer owns the wallet being debited, allowing any authenticated user, including one with only the Subscriber role, to move an arbitrary user's wallet balance, including an administrator's, into an account they control.

Proof of Concept

Affects Plugins

References

Classification

Type
IDOR
CWE

Miscellaneous

Original Researcher
Stefan Spasic
Submitter
Stefan Spasic
Verified
Yes

Timeline

Publicly Published
2026-10-06 (about 2 days ago)
Added
2026-10-06 (about 1 day ago)
Last Updated
2026-10-06 (about 1 day ago)

Other