PT-2026-3339 · Unknown+1 · Woocommerce+1

Published

2026-01-17

·

Updated

2026-01-17

·

CVE-2025-14450

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Wallet System for WooCommerce plugin for WordPress versions prior to 2.7.3
Description The Wallet System for WooCommerce plugin for WordPress has a flaw that allows unauthorized data modification. This is due to a missing capability check within the change wallet fund request status callback() function. Authenticated attackers possessing Subscriber-level access or higher can manipulate wallet withdrawal requests, potentially increasing their own wallet balance or decreasing the balances of other users.
Recommendations Update the Wallet System for WooCommerce plugin to version 2.7.3 or later.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-14450

Affected Products

Wallet System For Woocommerce
Woocommerce