All intelligence
// vulnerability record
cached · NVD via COSMOS syncCVE-2026-16538
CRITICALpublished 2026-08-12 06:19 UTC · 21 hours ago · modified 2026-08-12 20:17 UTC
9.1
CVSS / 10
// description
The Wallet for WooCommerce WordPress plugin before 1.6.10 does not verify the amount actually collected for a wallet top-up before crediting the wallet, allowing customers to top up their wallet balance for less than its value.
// weaknesses (CWE)
- CWE-284