Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-15045— Wallet System for WooCommerce < 2.7.10 - Customer+ Checkout Price Manipulation via Unvalidated Wallet Amount

CVSS 6.5 · Medium EPSS 0.19% · P10

Possible ATT&CK Techniques 1AI

T1190 · Exploit Public-Facing Application

Affected Version Matrix 1

VendorProductVersion RangeStatus
UnknownWallet System for WooCommerce< 2.7.10affected
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-15045

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Wallet System for WooCommerce < 2.7.10 - Customer+ Checkout Price Manipulation via Unvalidated Wallet Amount
Source: CVE Program / CVE List V5
Vulnerability Description
The Wallet System for WooCommerce WordPress plugin before 2.7.10 does not validate a user-supplied wallet amount against the customer's actual stored balance during checkout, allowing authenticated customers to arbitrarily reduce their own order total, including down to zero, and complete checkout without paying the merchant.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
WordPress Wallet System for WooCommerce 输入验证错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
WordPress Wallet System for WooCommerce是WordPress基金会的一款电子商务插件。 WordPress Wallet System for WooCommerce 2.7.10之前版本存在输入验证错误漏洞,该漏洞源于在结账过程中未将用户提供的钱包金额与客户实际存储余额进行验证,可能导致已认证客户任意减少其订单总额(包括降至零)并在不支付商家的情况下完成结账。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
UnknownWallet System for WooCommerce 0 ~ 2.7.10 -

II. Public POCs for CVE-2026-15045

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-15045

登录查看更多情报信息。

Vendor Advisories for CVE-2026-15045 (1)

Same Patch Batch · Unknown · 2026-08-12 · 44 CVEs total

CVE-2026-167476.5 MEDIUMKirki < 6.2.1 - Unauthenticated Arbitrary Shortcode Execution via Form Email Actions
CVE-2026-170085.3 MEDIUMQuick PayPal Payments <= 5.7.50 - Unauthenticated Payment Bypass via PayPal IPN
CVE-2026-169905.3 MEDIUMPayment Button for PayPal <= 1.2.3.44 - Unauthenticated Payment Price Manipulation
CVE-2026-152135.3 MEDIUMWelcart e-Commerce < 2.11.33 - Unauthenticated Payment Bypass via Forged Settlement Callba
CVE-2026-166215.3 MEDIUMPayment Gateway for PayPal on WooCommerce < 9.2.1 - Unauthenticated Payment Bypass via Pay
CVE-2026-180443.7 LOWEstatik Real Estate Plugin < 4.3.4 - Unauthenticated Arbitrary-Recipient Mail Relay via Si
CVE-2026-13168Eventin < 4.1.20 - Contributor+ Customer PII Disclosure via REST API
CVE-2026-16051WPMU DEV Dashboard < 5.0.1 - Remote Code Execution via Hub Install Action
CVE-2026-13613KiviCare < 4.5.2 - Doctor/Receptionist+ SQL Injection via settings/listing REST Endpoint
CVE-2026-13177Eventin < 4.1.20 - Contributor+ Order Information Disclosure via IDOR
CVE-2026-12976LearnPress < 4.4.4 - Subscriber+ Sensitive Information Exposure via AI Assistant
CVE-2026-13612KiviCare < 4.5.2 - Patient+ Cross-Patient Bill, Invoice and Appointment Disclosure via IDO
CVE-2026-15249Patterns Kit <= 1.0.3 - Contributor+ Stored XSS via YouTube Popup Link
CVE-2026-15039Gift Cards For WooCommerce Pro < 4.2.10 - Unauthenticated Arbitrary File Upload
CVE-2026-15388Cookie Consent < 0.0.10 - Subscriber+ Consent Settings Update and Consent Log Disclosure
CVE-2026-16538TeraWallet - Wallet for WooCommerce < 1.6.10 - Subscriber+ Wallet Balance Inflation via Di
CVE-2026-16066Welcart e-Commerce < 2.11.34 - Author+ Stored XSS via Product Name
CVE-2026-16253Total Upkeep (BoldGrid Backup) < 1.17.3 - Unauthenticated Sensitive Data Disclosure and Fo
CVE-2026-16294Blubrry PowerPress < 11.17.1 - Contributor+ Server-Side Request Forgery via Podcast Episod
CVE-2026-13171Eventin < 4.1.20 - Unauthenticated Account Creation via Waiting List Endpoint

Showing top 20 of 44 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-15045

No comments yet


Leave a comment