Junglewise Threat Intelligence

CVE-2026-42654: WP Swings Wallet System for WooCommerce authentication bypass in password recovery

CVE-2026-42654 · Severity: high · CVSS 7.1 · Published 2026-06-02

Technologies: WP Swings Wallet System for WooCommerce. Vendors: WP Swings.

Executive brief

A security vulnerability in the Wallet System for WooCommerce plugin allows unauthorized users to bypass standard security checks during the password recovery process. This plugin is used to manage digital wallets and customer credits on e-commerce sites. An attacker could exploit this flaw to gain access to other user accounts, potentially leading to the theft of digital funds or full administrative takeover of the online store.

Technical details

The Wallet System for WooCommerce plugin (versions 2.7.5 and earlier) is vulnerable to an authentication bypass via an alternate path or channel (CWE-288). The flaw resides in the password recovery logic, which fails to properly validate the identity of the requester through standard authentication channels. An attacker with low-level (Subscriber) privileges can exploit this to manipulate the password reset process and gain access to higher-privileged accounts. This vulnerability is exploitable over the network without user interaction. A fix is available in version 2.7.6.

Affected products

  • WP Swings Wallet System for WooCommerce <= 2.7.5

Timeline

  • 2026-03-16: other: Reported by Jakub Herman
  • 2026-04-29: advisory: Patchstack advisory published
  • 2026-06-02: disclosed: NVD publication date

References

Related threats