Wallet System for WooCommerce – Digital Wallet, Buy Now Pay Later (BNPL), Instant Cashback, Referral program, Partial & Subscription Payments

Information

Software Type Plugin
Software Slug wallet-system-for-woocommerce (view on wordpress.org)
Software Status Active
Software Author wpswings
Software Website wordpress.org
Software Downloads 135,874
Software Active Installs 2,000
Software Record Last Updated July 22, 2026

10 Vulnerabilities

Title Status CVE ID CVSS Researchers Date
Wallet System for WooCommerce – Digital Wallet, Buy Now Pay Later (BNPL), Instant Cashback, Referral program, Partial & Subscription Payments <= 2.7.6 - Missing Authorization Patched CVE-2026-57332 4.3 Evan NR June 29, 2026
Wallet System for WooCommerce – Digital Wallet, Buy Now Pay Later (BNPL), Instant Cashback, Referral program, Partial & Subscription Payments <= 2.7.5 - Missing Authorization Patched CVE-2026-42654 4.3 Jakub Herman April 29, 2026
Wallet System for WooCommerce <= 2.7.2 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Wallet Balance Manipulation Patched CVE-2025-14450 6.5 Md. Moniruzzaman Prodhan (NomanProdhan) January 16, 2026
Wallet System for WooCommerce <= 2.7.3 - Authenticated (Subscriber+) Information Exposure Patched CVE-2025-68029 4.3 Denver Jackson December 29, 2025
Wallet System for WooCommerce <= 2.6.7 - Cross-Site Request Forgery Patched CVE-2025-54041 4.3 Nguyen Xuan Chien July 16, 2025
Wallet System for WooCommerce <= 2.6.8 - Reflected Cross-Site Scripting Patched CVE-2025-32530 6.1 0xd4rk5id3 April 10, 2025
Wallet System for WooCommerce – Wallet, Wallet Cashback, Refunds, Partial Payment, Wallet Restriction <= 2.6.2 - Cross-Site Request Forgery Patched CVE-2024-13682 4.3 Tim Coen March 3, 2025
Wallet System for WooCommerce – Wallet, Wallet Cashback, Refunds, Partial Payment, Wallet Restriction <= 2.6.2 - Missing Authorization Patched CVE-2024-13724 4.3 Tim Coen March 3, 2025
Wallet System for WooCommerce <= 2.5.13 - Information Exposure via Log Files Patched CVE-2024-38699 5.3 Joshua Chan July 11, 2024
Wallet System for WooCommerce <= 2.5.9 - Cross-Site Request Forgery Patched CVE-2024-32446 4.3 Joshua Chan April 12, 2024

Did you know Wordfence Intelligence provides free personal and commercial API access to our comprehensive WordPress vulnerability database, along with a free webhook integration to stay on top of the latest vulnerabilities added and updated in the database? Get started today!

Learn more

Want to get notified of the latest vulnerabilities that may affect your WordPress site?
Install Wordfence on your site today to get notified immediately if your site is affected by a vulnerability that has been added to our database.

Get Wordfence

The Wordfence Intelligence WordPress vulnerability database is completely free to access and query via API. Please review the documentation on how to access and consume the vulnerability data via API.

Documentation