Executive brief
A security vulnerability exists in the Wallet System for WooCommerce plugin, which allows customers to maintain a digital balance on e-commerce sites. An attacker with a basic 'Subscriber' account (typically a standard customer login) can bypass security checks to perform actions they are not authorized to do. This could lead to unauthorized modifications of wallet data or disruption of the store's payment ecosystem.
Technical details
The Wallet System for WooCommerce plugin for WordPress is vulnerable to Broken Access Control due to missing authorization checks (CWE-862) in versions up to and including 2.7.6. An authenticated attacker with Subscriber-level permissions can exploit this flaw via network requests to execute functions that should be restricted to higher-privileged users. The vulnerability allows for unauthorized integrity changes and low-level availability impact. The issue is resolved in version 2.7.7.
Affected products
- WP Swings Wallet System for WooCommerce <= 2.7.6
Timeline
- 2026-04-17: disclosed: Reported by Evan NR
- 2026-06-29: advisory: Published by Patchstack and NVD
- 2026-06-29: patched: Version 2.7.7 released to address the issue