CVE-2026-42654: WordPress Wallet System for WooCommerce plugin <= 2.7.5 - Broken Authentication vulnerability
Authentication Bypass Using an Alternate Path or Channel vulnerability in WP Swings Wallet System for WooCommerce allows Password Recovery Exploitation.
This issue affects Wallet System for WooCommerce: from n/a through 2.7.5.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Wallet System for WooCommerce pluginto a version that resolves this vulnerability.Fixed in 2.7.6
Event History
Frequently Asked Questions
What is the severity of CVE-2026-42654?
CVE-2026-42654 has a severity rating of high, with a score of 7.1.
How do I fix CVE-2026-42654?
To remediate CVE-2026-42654, update the WordPress Wallet System for WooCommerce plugin to version 2.7.6 or later.
What impact does CVE-2026-42654 have on my site?
CVE-2026-42654 allows for authentication bypass that could enable unauthorized access through password recovery mechanisms.
Which versions of the plugin are affected by CVE-2026-42654?
CVE-2026-42654 affects the WP Swings Wallet System for WooCommerce plugin versions up to 2.7.5.
Who is impacted by CVE-2026-42654?
Any user using the WP Swings Wallet System for WooCommerce plugin version 2.7.5 or earlier may be impacted by CVE-2026-42654.