---
id: CVE-2026-94246
title: >-
  The Wallet System for WooCommerce  WordPress plugin before 2.8.0 does not
  verify that the wallet account named in a withdrawal submission belongs to the
  user making it, allowing any authenticated user, such as a subscriber, to file
  a wit…
summary: >-
  The Wallet System for WooCommerce  WordPress plugin before 2.8.0 does not
  verify that the wallet account named in a withdrawal submission belongs to the
  user making it, allowing any authenticated user, such as a subscriber, to file
  a wit…
severity: none
cwe:
  - CWE-639
product: Wallet System for WooCommerce
affected:
  - wallet_system_for_woocommerce >= 2.0.0 < 2.8.0
published: '2026-10-08'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T06:16:46.863'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-94246'
references:
  - url: 'https://wpscan.com/vulnerability/20949357-8fe6-4151-88b8-15abdef292cb/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-08T07:18:54.843Z'
---

## Overview

The Wallet System for WooCommerce  WordPress plugin before 2.8.0 does not verify that the wallet account named in a withdrawal submission belongs to the user making it, allowing any authenticated user, such as a subscriber, to file a withdrawal request against another user's wallet for an amount and a payout destination of their choosing, and to indefinitely prevent that user from submitting withdrawals of their own.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
