AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-15045

MEDIUM · CVSS 6.5 EPSS 0.19%

Source: NVD + CISA KEV + EPSS · Published 2026-08-12 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

The Wallet System for WooCommerce plugin for WordPress versions prior to 2.7.10 is vulnerable due to inadequate validation of user-supplied wallet amounts during the checkout process. This flaw allows authenticated customers to manipulate their order total, potentially reducing it to zero and completing purchases without payment, which poses a risk of financial loss to merchants. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate this vulnerability.

CVE
CVE-2026-15045
Severity
MEDIUM
CVSS
6.5
EPSS
0.19%
WordPress

Original NVD Description

The Wallet System for WooCommerce WordPress plugin before 2.7.10 does not validate a user-supplied wallet amount against the customer's actual stored balance during checkout, allowing authenticated customers to arbitrarily reduce their own order total, including down to zero, and complete checkout without paying the merchant.