PT-2026-3339 · Unknown+1 · Woocommerce+1

CVE-2025-14450

·

Publicado

2026-01-17

·

Atualizado

2026-01-17

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Wallet System for WooCommerce plugin for WordPress versions prior to 2.7.3
Description The Wallet System for WooCommerce plugin for WordPress has a flaw that allows unauthorized data modification. This is due to a missing capability check within the change wallet fund request status callback() function. Authenticated attackers possessing Subscriber-level access or higher can manipulate wallet withdrawal requests, potentially increasing their own wallet balance or decreasing the balances of other users.
Recommendations Update the Wallet System for WooCommerce plugin to version 2.7.3 or later.

Correção

Missing Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-14450

Produtos afetados

Wallet System For Woocommerce
Woocommerce