WordPress · Wallet System For Woocommerce · CVE-2026-94246
**Name of the Vulnerable Software and Affected Versions**
The Wallet System for WooCommerce WordPress plugin versions prior to 2.8.0
**Description**
The plugin fails to verify if the wallet account specified in a withdrawal submission belongs to the authenticated user initiating the request. This allows any authenticated user, including those with subscriber privileges, to submit withdrawal requests targeting another user's wallet, specifying a custom amount and payout destination. Additionally, this action can indefinitely block the targeted user from submitting their own withdrawals.
**Recommendations**
Update the plugin to version 2.8.0 or later.