CyberRota Analysis
AI-GeneratedThe Wallet System for WooCommerce plugin for WordPress versions prior to 2.7.10 is vulnerable due to inadequate validation of user-supplied wallet amounts during the checkout process. This flaw allows authenticated customers to manipulate their order total, potentially reducing it to zero and completing purchases without payment, which poses a risk of financial loss to merchants. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate this vulnerability.
Original NVD Description
The Wallet System for WooCommerce WordPress plugin before 2.7.10 does not validate a user-supplied wallet amount against the customer's actual stored balance during checkout, allowing authenticated customers to arbitrarily reduce their own order total, including down to zero, and complete checkout without paying the merchant.