CVE-2026-57332: WordPress Wallet System for WooCommerce plugin <= 2.7.6 - Broken Access Control vulnerability
Published Jun 29, 2026
·Updated
Subscriber Broken Access Control in Wallet System for WooCommerce <= 2.7.6 versions.
Affected Software
1 affected component
WooCommerce Wallet System for WooCommerce<=2.7.6
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Wallet System for WooCommerce pluginto a version that resolves this vulnerability.Fixed in 2.7.7
Event History
Jun 29, 2026
CVE Published
via MITRE·01:36 PM
Data Sourced
via MITRE·01:36 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·03:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-57332?
CVE-2026-57332 has a severity rating of high, with a score of 7.1.
2
What does CVE-2026-57332 exploit?
CVE-2026-57332 exploits a Broken Access Control vulnerability in the Wallet System for WooCommerce plugin versions <= 2.7.6.
3
How do I fix CVE-2026-57332?
To fix CVE-2026-57332, you should update the Wallet System for WooCommerce plugin to the latest version.
4
What impact does CVE-2026-57332 have on my WooCommerce site?
CVE-2026-57332 can allow authenticated users with subscriber privileges to escalate their access and potentially manipulate sensitive data.
5
When was CVE-2026-57332 published?
CVE-2026-57332 was published on June 29, 2026.