CVE-2026-93509

CVE-2026-93509 published: The Wallet System for WooCommerce WordPress plugin before 2.8.0 does not validate that a wallet transfer amount is positive, and computes the sender's new balance from a stale snapshot taken before crediting the recipient, allowing an authenticated attacker...

View full NVD advisory → ← Back to CVE watch