Sceawere

Vulnerability Detail

CVE-2026-16538UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Wallet for WooCommerce Balance Top-Up Validation Bypass

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.1
Creation Date
16h ago
Vendor
Unknown
Product
Wallet for WooCommerce
Attack Type
CWE-284 Improper Access Control
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Attack Complexity
LOW

Narrative and Response

Description

The Wallet for WooCommerce WordPress plugin before 1.6.10 does not verify the amount actually collected for a wallet top-up before crediting the wallet, allowing customers to top up their wallet balance for less than its value.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.1",
  "pubDate": "2026-08-12T06:19:10.620Z",
  "pubdate": "2026-08-12T06:19:10.620Z",
  "executiveSummary": "The Wallet for WooCommerce WordPress plugin before version 1.6.10 suffers from an insufficient financial transaction verification vulnerability during wallet top-up operations. This flaw allows authenticated users to manipulate the funding process and credit their digital wallets with arbitrary balances while paying less than the intended amount. The vulnerability poses a significant financial risk to merchants utilizing the affected plugin, as malicious actors can exploit the payment verification gap to acquire unearned store credit without corresponding monetary transactions. The risk implications include direct financial loss, fraudulent resource accumulation, and potential abuse of e-commerce checkout systems. Exploitation requires standard user interaction within the WooCommerce ecosystem, specifically the ability to initiate and manipulate a wallet top-up transaction before server-side validation completes.",
  "technicalDetails": "The root cause of this vulnerability lies in the application's failure to properly verify and reconcile the actual amount collected by the payment gateway against the amount requested for the wallet top-up before updating the user balance. Specifically, the vulnerable component processes the wallet crediting logic based on client-supplied parameters or unvalidated transaction states rather than performing a secure server-side verification callback or webhook confirmation with the underlying payment processor. In a typical attack flow, an attacker initiates a wallet top-up request for a high value, intercepts or modifies the payment parameters or checkout sequence to remit a significantly lower monetary amount, and completes the payment gateway interaction. Because the Wallet for WooCommerce plugin lacks strict cryptographic or state-based validation to ensure that the collected payment matches the requested wallet credit amount, the backend application trusts the transaction and credits the user account with the full requested balance. The affected versions include all instances of the Wallet for WooCommerce WordPress plugin prior to version 1.6.10. The vulnerability is exploitable over the network by any authenticated user with access to the wallet top-up functionality. No elevated administrative privileges are required, as standard customer accounts can execute the attack flow. Post-exploitation impact involves the unauthorized accumulation of digital wallet funds, which can subsequently be utilized to purchase physical or digital goods within the compromised WooCommerce store, resulting in direct revenue loss and economic fraud."
}
CVE-2026-16538: Wallet for WooCommerce Balance Top-Up Validation Bypass (CRITICAL Severity, CVSS: 9.1) - Sceawere