PT-2026-107848 · WordPress · Wallet System For Woocommerce
CVSS v3.1
6.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
The Wallet System for WooCommerce WordPress plugin versions prior to 2.8.0
Description
The plugin fails to verify if the wallet account specified in a withdrawal submission belongs to the authenticated user initiating the request. This allows any authenticated user, including those with subscriber privileges, to submit withdrawal requests targeting another user's wallet, specifying a custom amount and payout destination. Additionally, this action can indefinitely block the targeted user from submitting their own withdrawals.
Recommendations
Update the plugin to version 2.8.0 or later.
Exploit
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wallet System For Woocommerce