CVE-2026-94244: Wallet System for WooCommerce < 2.8.0 - Subscriber+ Store-Wide Wallet Transaction Disclosure via Export
The Wallet System for WooCommerce WordPress plugin before 2.8.0 does not perform any capability check, and relies on a token any authenticated user can obtain from a front-end page, before generating a report containing every customer's wallet transaction history, allowing any authenticated user, such as a subscriber, to disclose all users' names, email addresses, roles, transaction amounts, payment methods and dates.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
Any authenticated WordPress user can exploit it, including users with only the Subscriber role. The attacker can obtain the required token from a front-end page; no administrative capability check is enforced.
What information can be exposed?
The generated report contains wallet transaction history for every customer. Exposed fields include users' names, email addresses, roles, transaction amounts, payment methods, and transaction dates.
Which plugin versions are affected?
Wallet System for WooCommerce versions earlier than 2.8.0 are affected. Version 2.8.0 is the first version identified as not affected.