CVE-2026-12103: Wallet for WooCommerce <= 1.6.4 - Missing Authorization to Authenticated (Subscriber+) User/Email Enumeration via terawallet_export_user_search AJAX Action
The Wallet for WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.6.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to enumerate the login name, email address, and user ID of all WordPress accounts — including administrators — by submitting arbitrary search terms to the AJAX handler. The required 'search-user' nonce is localized into the walletparam object on the standard WooCommerce My Account page, which is accessible to any authenticated user, making it trivially obtainable by a Subscriber.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress plugin: Wallet for WooCommerceto a version that resolves this vulnerability.Fixed in 1.6.4 - Upgrade
Upgrade
WordPress plugin: Wallet for WooCommerceto a version that resolves this vulnerability.Fixed in 1.6.4Patch Wallet for WooCommerce <= 1.6.4 - Missing Authorization to Authenticated (Subscriber+) User/Email Enumeration via terawallet_export_user_search AJAX Action
Event History
Frequently Asked Questions
What is the severity of CVE-2026-12103?
The severity of CVE-2026-12103 is medium with a CVSS score of 4.3.
How do I fix CVE-2026-12103?
To fix CVE-2026-12103, update the Wallet for WooCommerce plugin to the latest version that addresses this vulnerability.
What actions can authenticated users perform due to CVE-2026-12103?
Authenticated users may be able to enumerate user email addresses due to the lack of proper authorization checks in CVE-2026-12103.
Which versions of the Wallet for WooCommerce are affected by CVE-2026-12103?
CVE-2026-12103 affects all versions of the Wallet for WooCommerce plugin up to and including 1.6.4.
Why is CVE-2026-12103 a security concern?
CVE-2026-12103 is a security concern because it allows unauthorized actions that can lead to user data exposure and potential privacy violations.