CVE-2026-16538
Deferred Deferred - Pending Action

Wallet Top-Up Amount Validation Bypass in WooCommerce Plugin

Vulnerability report for CVE-2026-16538, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-12

Last updated on: 2026-08-26

Assigner: WPScan

Description

The Wallet for WooCommerce WordPress plugin before 1.6.10 does not verify the amount actually collected for a wallet top-up before crediting the wallet, allowing customers to top up their wallet balance for less than its value.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-12
Last Modified
2026-08-26
Generated
2026-09-01
AI Q&A
2026-08-12
EPSS Evaluated
2026-08-31
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
terawallet wallet_for_woocommerce to 1.6.10 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-284 The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The Wallet for WooCommerce plugin before version 1.6.10 has a flaw where it does not check the actual payment amount during wallet top-ups. This allows users to pay less than the intended value while still receiving the full credited amount in their wallet.

Detection Guidance

To detect this vulnerability, check the installed version of the TeraWallet – Wallet for WooCommerce plugin. If the version is below 1.6.10, the system is vulnerable. Use commands like 'wp plugin list' in WordPress CLI or inspect the plugin files directly.

Impact Analysis

Users with Subscriber-level access or higher can exploit this to inflate their wallet balance by paying less than the top-up value. This could lead to financial losses for the store owner if customers exploit it repeatedly.

Compliance Impact

This vulnerability could potentially affect compliance with financial and data protection regulations by enabling unauthorized wallet balance inflation. For GDPR, it may lead to improper financial data processing if user transactions are mishandled. For HIPAA, if the plugin handles health-related payments, incorrect wallet balances could violate financial integrity requirements.

Mitigation Strategies

Immediately update the TeraWallet – Wallet for WooCommerce plugin to version 1.6.10 or later. Remove or restrict Subscriber-level access to prevent unauthorized top-up manipulations until the update is applied.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-16538. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart