WordPress · Wallet System For Woocommerce · CVE-2024-13682
**Name of the Vulnerable Software and Affected Versions**
The Wallet System for WooCommerce – Wallet, Wallet Cashback, Refunds, Partial Payment, Wallet Restriction plugin for WordPress versions up to, and including, 2.6.2
**Description**
The issue is related to Cross-Site Request Forgery due to missing or incorrect nonce validation in the class-wallet-user-table.php file. This allows unauthenticated attackers to modify wallet balances by tricking a site administrator into performing a specific action, such as clicking on a link.
**Recommendations**
For versions up to, and including, 2.6.2, update to a version that includes the fix for the missing or incorrect nonce validation in the class-wallet-user-table.php file.
As a temporary workaround, consider restricting access to the wallet balance modification functionality to prevent exploitation.