CVE-2026-16538: TeraWallet - Wallet for WooCommerce < 1.6.10 - Subscriber+ Wallet Balance Inflation via Discounted Top-Up
Published Aug 12, 2026
·Updated
The Wallet for WooCommerce WordPress plugin before 1.6.10 does not verify the amount actually collected for a wallet top-up before crediting the wallet, allowing customers to top up their wallet balance for less than its value.
Affected Software
1 affected component
WordPress plugin "Wallet for WooCommerce" (TeraWallet)<1.6.10
Event History
Aug 12, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·06:19 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2026-16538?
CVE-2026-16538 has a risk score of 45, indicating a medium-level severity.
2
How do I fix CVE-2026-16538?
To fix CVE-2026-16538, update the Wallet for WooCommerce plugin to version 1.6.10 or later.
3
What does CVE-2026-16538 affect?
CVE-2026-16538 affects the Wallet for WooCommerce WordPress plugin versions prior to 1.6.10.
4
What type of vulnerability is CVE-2026-16538?
CVE-2026-16538 is a wallet balance inflation vulnerability that allows improper crediting of wallet amounts.
5
Who is impacted by CVE-2026-16538?
Customers using the Wallet for WooCommerce plugin prior to version 1.6.10 are at risk from CVE-2026-16538.