Sceawere
Vulnerability Detail
CVE-2026-94246UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Insecure IDOR in Wallet System
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.3
- Creation Date
- 8h ago
- Vendor
- Unknown
- Product
- Wallet System for WooCommerce
- Attack Type
- CWE-639 Authorization Bypass Through User-Controlled Key
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
The Wallet System for WooCommerce WordPress plugin before 2.8.0 does not verify that the wallet account named in a withdrawal submission belongs to the user making it, allowing any authenticated user, such as a subscriber, to file a withdrawal request against another user's wallet for an amount and a payout destination of their choosing, and to indefinitely prevent that user from submitting withdrawals of their own.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.3",
"pubDate": "2026-10-08T06:16:46.863Z",
"pubdate": "2026-10-08T06:16:46.863Z",
"executiveSummary": "The Wallet System for WooCommerce WordPress plugin, in versions prior to 2.8.0, is affected by an Insecure Direct Object Reference (IDOR) vulnerability within its withdrawal submission functionality.\nThis vulnerability exists because the application fails to perform adequate server-side authorization checks to verify that the requesting user owns the wallet account specified in a withdrawal request.\nAny authenticated user, including those with minimal privileges such as subscribers, can submit fraudulent withdrawal requests targeting arbitrary user accounts.\nThis allows attackers to manipulate the financial data of other users, initiate unauthorized payouts to destination accounts of their choice, and conduct denial-of-service attacks by exhausting withdrawal queues or placing the target's wallet in a state that prevents legitimate user-initiated withdrawals.\nThe flaw represents a significant security risk, potentially leading to financial fraud and unauthorized asset movement.\nExploitation requires only a valid user account on the WordPress installation, making it highly accessible to malicious actors.",
"technicalDetails": "The root cause of this vulnerability is a failure in the authorization logic during the processing of withdrawal submissions. The plugin processes requests where the user-supplied wallet identifier is not cryptographically bound or server-side validated against the currently authenticated user's session identifier (UID).\nUnder normal circumstances, a withdrawal request should initiate a look-up to confirm the requester possesses ownership rights to the wallet being debited. In affected versions, the backend logic accepts the provided wallet name as a trusted parameter without validating ownership.\nThe attack flow begins when an authenticated subscriber identifies the parameters required for a withdrawal request, likely via a POST request intercepted or crafted to interact with the plugin's withdrawal endpoint.\nAn attacker can systematically supply the identifier of another user's wallet. Because the plugin does not verify the relationship between the session user and the target wallet, the application proceeds to process the request as if it were legitimate.\nBy submitting these forged requests, an attacker can designate an arbitrary payout destination and amount. This allows for the redirection of funds to an account controlled by the attacker if the payout destination can be manipulated.\nFurthermore, the logic allows for an effective denial-of-service attack against the victim. By flooding the system with withdrawal requests associated with a victim's account, the attacker can indefinitely block the legitimate user from submitting their own valid withdrawal requests. This results in the freezing of the user's ability to manage their funds within the plugin.\nThe lack of server-side state validation regarding user-to-account mapping allows for complete bypass of account access controls. The impact is elevated by the fact that no special permissions beyond basic authentication are required, meaning any registered user account—even one created solely for exploitation—can target any wallet registered within the plugin environment.\nBecause this occurs at the application level during the submission processing flow, it bypasses standard client-side restrictions. The vulnerability persists across all instances of the plugin below version 2.8.0, regardless of specific WooCommerce configurations, provided the Wallet System module is active."
}