{"id":"CVE-2026-93509","title":"The Wallet System for WooCommerce WordPress plugin before 2.8.0 does not validate that a wallet transfer amount is positive, and computes the sender's new balance from a stale snapshot taken before crediting the recipient, allowing an au…","summary":"The Wallet System for WooCommerce WordPress plugin before 2.8.0 does not validate that a wallet transfer amount is positive, and computes the sender's new balance from a stale snapshot taken before crediting the recipient, allowing an au…","severity":"medium","cvss":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","cwe":["CWE-20"],"product":"Wallet System for WooCommerce","affected":["wallet_system_for_woocommerce >= 2.0.0 < 2.8.0"],"published":"2026-10-08","updated":"2026-10-08","sourceUpdated":"2026-10-08T20:51:18.123","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-93509","references":[{"url":"https://wpscan.com/vulnerability/a31138af-234e-44c8-bced-9058553a8b81/","label":"contact@wpscan.com"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-10-08T10:52:54.918308Z"},"ingestedAt":"2026-10-08T11:31:27.691Z","slug":"CVE-2026-93509","body":"## Overview\n\nThe Wallet System for WooCommerce WordPress plugin before 2.8.0 does not validate that a wallet transfer amount is positive, and computes the sender's new balance from a stale snapshot taken before crediting the recipient, allowing an authenticated attacker with Subscriber-level access to mint wallet funds for themselves or drain a specific victim's balance into their own account.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":36,"depthScoreParts":{"impact":35.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}