CVE-2026-16538

9.1

WordPress · Wallet for WooCommerce

The Wallet for WooCommerce plugin fails to verify payment completion before crediting user wallets, allowing attackers to inflate balances without providing valid payment.

Executive summary

A critical business logic vulnerability in the Wallet for WooCommerce plugin allows unauthenticated users to gain unauthorized wallet credit, resulting in direct financial loss.

Vulnerability

The plugin suffers from an improper access control flaw where the system credits wallet balances without confirming successful transaction processing from the payment gateway. This allows unauthenticated users to manipulate the top-up process to receive funds without actual payment.

Business impact

This vulnerability carries a CVSS score of 9.1, reflecting its critical potential for direct financial theft. Successful exploitation allows malicious actors to artificially inflate their wallet balances, which can be used to purchase goods or services, causing significant revenue loss and inventory depletion for merchants.

Remediation

Immediate Action: Update the Wallet for WooCommerce plugin to version 1.6.10 or later immediately.

Proactive Monitoring: Review transaction logs for discrepancies where wallet credits exist without corresponding successful payment gateway records.

Compensating Controls: If an immediate update is not possible, temporarily disable the wallet top-up functionality until the patch can be applied.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the critical severity and the potential for direct financial impact, administrators must prioritize this update. Ensure that all plugin instances are patched to version 1.6.10 to prevent unauthorized wallet balance inflation.

More WordPress CVEs