{"id":"CVE-2026-94246","title":"The Wallet System for WooCommerce  WordPress plugin before 2.8.0 does not verify that the wallet account named in a withdrawal submission belongs to the user making it, allowing any authenticated user, such as a subscriber, to file a wit…","summary":"The Wallet System for WooCommerce  WordPress plugin before 2.8.0 does not verify that the wallet account named in a withdrawal submission belongs to the user making it, allowing any authenticated user, such as a subscriber, to file a wit…","severity":"none","cwe":["CWE-639"],"product":"Wallet System for WooCommerce","affected":["wallet_system_for_woocommerce >= 2.0.0 < 2.8.0"],"published":"2026-10-08","updated":"2026-10-08","sourceUpdated":"2026-10-08T06:16:46.863","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-94246","references":[{"url":"https://wpscan.com/vulnerability/20949357-8fe6-4151-88b8-15abdef292cb/","label":"contact@wpscan.com"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-10-08T07:18:54.843Z","slug":"CVE-2026-94246","body":"## Overview\n\nThe Wallet System for WooCommerce  WordPress plugin before 2.8.0 does not verify that the wallet account named in a withdrawal submission belongs to the user making it, allowing any authenticated user, such as a subscriber, to file a withdrawal request against another user's wallet for an amount and a payout destination of their choosing, and to indefinitely prevent that user from submitting withdrawals of their own.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}