Medium severity4.3NVD Advisory· Published Mar 4, 2025· Updated Jun 17, 2026
CVE-2024-13682
CVE-2024-13682
Description
The Wallet System for WooCommerce – Wallet, Wallet Cashback, Refunds, Partial Payment, Wallet Restriction plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.6.2. This is due to missing or incorrect nonce validation in class-wallet-user-table.php. This makes it possible for unauthenticated attackers to modify wallet balances via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Affected products
3- cpe:2.3:a:wpswings:wallet_system_for_woocommerce:*:*:*:*:*:wordpress:*:*Range: <2.6.3
- Range: <=2.6.2
- wpswings/Wallet System for WooCommerce – Digital Wallet, Buy Now Pay Later (BNPL), Instant Cashback, Referral program, Partial & Subscription Paymentsv5Range: 0
Patches
Vulnerability mechanics
References
2- plugins.trac.wordpress.org/changesetnvdPatch
- www.wordfence.com/threat-intel/vulnerabilities/id/779a9f7a-4582-4d5e-bd9a-9ff7f14b452anvdThird Party Advisory
News mentions
0No linked articles in our index yet.