Sceawere
Vulnerability Detail
CVE-2026-94245UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Insecure Direct Object Reference Wallet Transfer
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.5
- Creation Date
- 8h ago
- Vendor
- Unknown
- Product
- Wallet System for WooCommerce
- Attack Type
- CWE-639 Authorization Bypass Through User-Controlled Key
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
The Wallet System for WooCommerce WordPress plugin before 2.8.0 does not verify that the user submitting a wallet transfer owns the wallet being debited, allowing any authenticated user, including one with only the Subscriber role, to move an arbitrary user's wallet balance, including an administrator's, into an account they control.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.5",
"pubDate": "2026-10-08T06:16:46.533Z",
"pubdate": "2026-10-08T06:16:46.533Z",
"executiveSummary": "The Wallet System for WooCommerce WordPress plugin contains a critical Insecure Direct Object Reference (IDOR) vulnerability due to insufficient authorization checks in its wallet transfer functionality.\nThe vulnerability resides in versions prior to 2.8.0. By failing to validate the ownership of the source wallet during a transfer request, the plugin allows any authenticated user to illicitly transfer funds from arbitrary user accounts, including those with administrative privileges, to an account under the attacker's control.\nThe impact is significant, as it facilitates unauthorized financial gain and balance manipulation. This vulnerability poses a severe risk to the integrity of the store's financial ecosystem.\nExploitation requires only an authenticated user account (such as a Subscriber), meaning no elevated privileges are necessary to initiate the attack. Once the request is crafted to target a specific victim's wallet ID, the system processes the unauthorized debit without further verification of the requester's permissions over the source object.",
"technicalDetails": "The root cause of this vulnerability is a failure in the server-side access control mechanism within the Wallet System for WooCommerce plugin. Specifically, the transfer processing logic assumes that any request directed toward the transfer endpoint is authorized by the owner of the source wallet.\nWhen a transfer request is initiated, the application fails to perform a cross-reference check between the current session's authenticated user ID and the ID of the wallet being debited. This represents a classic IDOR flaw where the application relies solely on the user-supplied input to identify the source of the transaction without enforcing strict ownership validation.\nThe exploitation flow proceeds as follows: First, the attacker, logged in as a standard Subscriber, intercepts or constructs a POST request intended for the transfer functionality. The request typically includes parameters identifying the source wallet (e.g., a numeric user ID or a unique wallet identifier) and the destination wallet.\nBecause the server-side code does not verify the requester's authorization against the provided source identifier, the attacker can modify the source wallet parameter to match an administrator or another high-value user. Upon submission, the plugin's backend processes the logic to deduct the specified amount from the victim's wallet and credit it to the attacker's wallet.\nThe vulnerable component involves the server-side controller or callback function responsible for handling wallet-to-wallet transfers. By manipulating the transaction parameters, the attacker can drain funds from any user account visible to the system. Since the application fails to validate the current user's session against the object being acted upon, the check is bypassed entirely.\nThe post-exploitation impact includes complete depletion of victim wallet balances and unauthorized financial gain. Given that WooCommerce wallet systems are often linked to real-currency credits, this vulnerability allows for direct financial fraud. Because the exploit is triggered via standard application requests, it remains highly effective as long as the victim's wallet identifier is discoverable or predictable."
}