Sceawere
Vulnerability Detail
CVE-2026-94244UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Wallet System Information Disclosure
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 4.3
- Creation Date
- 8h ago
- Vendor
- Unknown
- Product
- Wallet System for WooCommerce
- Attack Type
- CWE-200 Information Exposure
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
The Wallet System for WooCommerce WordPress plugin before 2.8.0 does not perform any capability check, and relies on a token any authenticated user can obtain from a front-end page, before generating a report containing every customer's wallet transaction history, allowing any authenticated user, such as a subscriber, to disclose all users' names, email addresses, roles, transaction amounts, payment methods and dates.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "4.3",
"pubDate": "2026-10-08T06:16:46.197Z",
"pubdate": "2026-10-08T06:16:46.197Z",
"executiveSummary": "The Wallet System for WooCommerce WordPress plugin, in versions prior to 2.8.0, contains a critical security vulnerability involving the lack of authorization checks for generating sensitive transaction reports.\nThe vulnerability is categorized as an improper access control issue, which allows any authenticated user—including those with minimal privileges like subscribers—to access the comprehensive transaction histories of all customers.\nThe scope of exposed data includes full names, email addresses, assigned user roles, precise transaction amounts, payment method details, and transaction timestamps.\nThis represents a significant breach of data privacy and internal business intelligence. The exploitation requires only a valid user account on the WordPress site, making it accessible to any registered user.\nSuccessful exploitation results in the unauthorized mass exfiltration of sensitive Personally Identifiable Information (PII) and financial transaction data, posing severe compliance risks regarding data protection regulations such as GDPR or CCPA.",
"technicalDetails": "The root cause of this vulnerability lies in the improper implementation of access control mechanisms within the plugin's reporting functionality. The application fails to validate the user's capabilities or permissions before executing the report generation logic.\nThe exploitation process begins with the attacker obtaining a valid session token, which is readily accessible to any authenticated user via the front-end interface of the WordPress site. Because the plugin does not verify if the user possesses administrative or shop-manager privileges, this token is sufficient to authorize requests that should be strictly restricted.\nWhen a user triggers the reporting function, the application processes the request server-side without an authorization check (e.g., current_user_can() in WordPress). Consequently, the underlying function executes a database query to aggregate all wallet transactions across the entire WooCommerce store.\nThe attack flow is straightforward: 1) The attacker authenticates as a standard user. 2) The attacker retrieves the required security token from the front-end. 3) The attacker sends a crafted request targeting the report generation endpoint/handler. 4) The server processes the request and returns a structured output containing the full transactional history of the system.\nThis vulnerability is classified as an insecure direct object reference or missing function-level access control, specifically within the module responsible for generating CSV or data reports. The lack of granular capability checks means the plugin fails to enforce the principle of least privilege, allowing an authenticated user to act as an unprivileged data scraper.\nThe post-exploitation impact is severe, as the attacker can exfiltrate the entire user base's PII and financial metadata. This data is highly valuable for secondary attacks, such as spear-phishing campaigns or targeted fraud, based on the exposed payment methods and transaction history."
}