Sceawere
Vulnerability Detail
CVE-2026-16538UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Wallet for WooCommerce Balance Top-Up Validation Bypass
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 9.1
- Creation Date
- 16h ago
- Vendor
- Unknown
- Product
- Wallet for WooCommerce
- Attack Type
- CWE-284 Improper Access Control
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
The Wallet for WooCommerce WordPress plugin before 1.6.10 does not verify the amount actually collected for a wallet top-up before crediting the wallet, allowing customers to top up their wallet balance for less than its value.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "9.1",
"pubDate": "2026-08-12T06:19:10.620Z",
"pubdate": "2026-08-12T06:19:10.620Z",
"executiveSummary": "The Wallet for WooCommerce WordPress plugin before version 1.6.10 suffers from an insufficient financial transaction verification vulnerability during wallet top-up operations. This flaw allows authenticated users to manipulate the funding process and credit their digital wallets with arbitrary balances while paying less than the intended amount. The vulnerability poses a significant financial risk to merchants utilizing the affected plugin, as malicious actors can exploit the payment verification gap to acquire unearned store credit without corresponding monetary transactions. The risk implications include direct financial loss, fraudulent resource accumulation, and potential abuse of e-commerce checkout systems. Exploitation requires standard user interaction within the WooCommerce ecosystem, specifically the ability to initiate and manipulate a wallet top-up transaction before server-side validation completes.",
"technicalDetails": "The root cause of this vulnerability lies in the application's failure to properly verify and reconcile the actual amount collected by the payment gateway against the amount requested for the wallet top-up before updating the user balance. Specifically, the vulnerable component processes the wallet crediting logic based on client-supplied parameters or unvalidated transaction states rather than performing a secure server-side verification callback or webhook confirmation with the underlying payment processor. In a typical attack flow, an attacker initiates a wallet top-up request for a high value, intercepts or modifies the payment parameters or checkout sequence to remit a significantly lower monetary amount, and completes the payment gateway interaction. Because the Wallet for WooCommerce plugin lacks strict cryptographic or state-based validation to ensure that the collected payment matches the requested wallet credit amount, the backend application trusts the transaction and credits the user account with the full requested balance. The affected versions include all instances of the Wallet for WooCommerce WordPress plugin prior to version 1.6.10. The vulnerability is exploitable over the network by any authenticated user with access to the wallet top-up functionality. No elevated administrative privileges are required, as standard customer accounts can execute the attack flow. Post-exploitation impact involves the unauthorized accumulation of digital wallet funds, which can subsequently be utilized to purchase physical or digital goods within the compromised WooCommerce store, resulting in direct revenue loss and economic fraud."
}