What is CVE-2026-16538?
CVE-2026-16538 is a vulnerability in the Wallet for WooCommerce WordPress plugin before version 1.6.10. It fails to verify the amount collected before crediting the wallet, allowing customers to top up their balance for less than its actual value. Users should update the plugin to the latest version immediately.
Azərbaycanca: CVE-2026-16538, WooCommerce üçün Wallet plaqininin 1.6.10-dan əvvəlki versiyalarında aşkarlanan boşluqdur. Bu zəiflik ödəniş məbləğini doğrulamadığı üçün müştərilərə cüzdanı dəyərindən daha az məbləğlə doldurmağa imkan verir. Təsirə məruz qalan sistemlərdə plaqini dərhal ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-20
FAQ2
Which plugin is affected by CVE-2026-16538 and in which versions does the issue exist?
The vulnerability exists in the Wallet for WooCommerce WordPress plugin before version 1.6.10.
How can I protect my system from CVE-2026-16538?
Users should update the plugin to the latest version immediately.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.