Broken Access Control in Wallet System for WooCommerce by Patchstack
CVE-2026-57332

7.1HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
29 June 2026

What is CVE-2026-57332?

The Wallet System for WooCommerce version 2.7.6 and earlier is susceptible to a broken access control vulnerability that could allow unauthorized access to certain functionalities. This flaw could potentially enable malicious users to engage in unauthorized actions, compromising the integrity of your online transactions and user accounts. It is essential to update immediately to protect your eCommerce environment from potential exploitation.

Affected Version(s)

Wallet System for WooCommerce <= 2.7.6

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Evan NR | Patchstack Bug Bounty Program
.