What the vulnerability does
01Description
Missing Authorization vulnerability in WP Swings Wallet System for WooCommerce allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Wallet System for WooCommerce: from n/a through 2.5.13.
Explanation of Vulnerability in Simple Terms
02Summary
The Wallet System for WooCommerce plugin fails to verify user permissions before allowing access to sensitive wallet operations. An unauthenticated attacker can read wallet data and transaction history from any user account without logging in. This affects all versions up to 2.5.13. Site owners should update immediately to a patched version.
What an attacker can do
03Attacker Capabilities
Read any user's wallet balance, transaction history, and payment details without authentication.
Potential impact on your site
04Site Impact
Customer financial data and wallet transactions are exposed to anyone on the internet who knows the plugin is installed.
Conditions required to exploit
05Prerequisites
None. The attacker needs only network access to the site; no login or user interaction required.
Key dates
06Disclosure timeline
August 13, 2024
CVE published
April 28, 2026
Record updated