Wpswings
Wpswings Wallet System FOR Woocommerce: vulnerabilidades y CVE
Wpswings Wallet System FOR Woocommerce tiene 11 vulnerabilidades publicadas, 5 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE11
Últimos 12 meses5
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-15045 | Media (6.5) | 0.34% | — | 12 ago 2026 | The Wallet System for WooCommerce WordPress plugin before 2.7.10 does not validate a user-supplied wallet amount against the customer's actual stored balance during checkout, allowing authenticated customers to… |
| CVE-2026-57332 | Alta (7.1) | 0.34% | — | 29 jun 2026 | Subscriber Broken Access Control in Wallet System for WooCommerce <= 2.7.6 versions. |
| CVE-2026-42654 | Alta (7.1) | 0.37% | — | 2 jun 2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in WP Swings Wallet System for WooCommerce allows Password Recovery Exploitation. This issue affects Wallet System for WooCommerce: from n/a through… |
| CVE-2025-14450 | Media (6.5) | 0.25% | — | 17 ene 2026 | The Wallet System for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'change_wallet_fund_request_status_callback' function in all versions up… |
| CVE-2025-68029 | Media (6.3) | 0.20% | — | 5 ene 2026 | Insertion of Sensitive Information Into Sent Data vulnerability in WP Swings Wallet System for WooCommerce wallet-system-for-woocommerce allows Retrieve Embedded Sensitive Data.This issue affects Wallet System for… |
| CVE-2025-54041 | Media (4.3) | 0.13% | — | 16 jul 2025 | Cross-Site Request Forgery (CSRF) vulnerability in WP Swings Wallet System for WooCommerce wallet-system-for-woocommerce allows Cross Site Request Forgery.This issue affects Wallet System for WooCommerce: from n/a… |
| CVE-2025-32530 | Alta (7.1) | 0.29% | — | 17 abr 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Swings Wallet System for WooCommerce wallet-system-for-woocommerce allows Reflected XSS.This issue affects Wallet… |
| CVE-2024-13724 | Media (4.3) | 0.25% | — | 4 mar 2025 | The Wallet System for WooCommerce – Wallet, Wallet Cashback, Refunds, Partial Payment, Wallet Restriction plugin for WordPress is vulnerable to unauthorized access to functionality in all versions up to, and including,… |
| CVE-2024-13682 | Media (4.3) | 0.15% | — | 4 mar 2025 | The Wallet System for WooCommerce – Wallet, Wallet Cashback, Refunds, Partial Payment, Wallet Restriction plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.6.2.… |
| CVE-2024-38699 | Alta (7.5) | 0.42% | — | 13 ago 2024 | Missing Authorization vulnerability in WP Swings Wallet System for WooCommerce allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Wallet System for WooCommerce: from n/a through 2.5.13. |
| CVE-2024-32446 | Media (5.4) | 0.21% | — | 15 abr 2024 | Cross-Site Request Forgery (CSRF) vulnerability in WP Swings Wallet System for WooCommerce.This issue affects Wallet System for WooCommerce: from n/a through 2.5.9. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.
Otros productos de Wpswings
Return Refund AND Exchange FOR Woocommerce · 7Membership FOR Woocommerce · 7Ultimate Gift Cards FOR Woocommerce · 6Points AND Rewards FOR Woocommerce · 4Woocommerce Ultimate Gift Card · 3PDF Generator FOR Wordpress · 2Coupon Referral Program · 2Subscriptions FOR Woocommerce · 2Woocommerce Ultimate Points AND Rewards · 1Event Tickets Manager FOR Woocommerce · 1Gift Cards FOR Woocommerce PRO · 1Mautic Integration FOR Woocommerce · 1