Executive brief
A security vulnerability in the Wallet System for WooCommerce plugin allows unauthorized users to bypass standard security checks during the password recovery process. This plugin is used to manage digital wallets and customer credits on e-commerce sites. An attacker could exploit this flaw to gain access to other user accounts, potentially leading to the theft of digital funds or full administrative takeover of the online store.
Technical details
The Wallet System for WooCommerce plugin (versions 2.7.5 and earlier) is vulnerable to an authentication bypass via an alternate path or channel (CWE-288). The flaw resides in the password recovery logic, which fails to properly validate the identity of the requester through standard authentication channels. An attacker with low-level (Subscriber) privileges can exploit this to manipulate the password reset process and gain access to higher-privileged accounts. This vulnerability is exploitable over the network without user interaction. A fix is available in version 2.7.6.
Affected products
- WP Swings Wallet System for WooCommerce <= 2.7.5
Timeline
- 2026-03-16: other: Reported by Jakub Herman
- 2026-04-29: advisory: Patchstack advisory published
- 2026-06-02: disclosed: NVD publication date