CVE WATCH / VULNERABILITY DETAIL
CVE-2026-94246
MEDIUMCVSS 6.3NVD feed
Published 8 October 2026 · tracked since 8 October 2026
Description
The Wallet System for WooCommerce WordPress plugin before 2.8.0 does not verify that the wallet account named in a withdrawal submission belongs to the user making it, allowing any authenticated user, such as a subscriber, to file a withdrawal request against another user's wallet for an amount and
References
- NVD — National Vulnerability Database
- CVE.org record (MITRE)
- CISA Known Exploited Vulnerabilities catalog
Latest tracked vulnerabilities
- CVE-2026-107573 HIGH 7.8
- CVE-2026-107275 MEDIUM 6.8
- CVE-2026-93509 MEDIUM 6.5
- CVE-2026-104660 HIGH 7.8
- CVE-2026-104671 MEDIUM 5.3
- CVE-2026-105190 MEDIUM 5.3
- CVE-2026-103649 HIGH 7.5
- CVE-2026-103010 HIGH 7.8
- CVE-2026-103011 MEDIUM 6.5
- CVE-2026-103517 MEDIUM 5.3