CVE-2026-16538

Summary

The Wallet for WooCommerce WordPress plugin before 1.6.10 does not verify the amount actually collected for a wallet top-up before crediting the wallet, allowing customers to top up their wallet balance for less than its value.

Affected Software

VendorProductVersion RangeStatus
UnknownWallet for WooCommerce0 < 1.6.10affected

Weaknesses

  • CWE-284 Improper Access Control

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: poc
    • Automatable: yes
    • Technical Impact: total

References