CVE-2026-42654

HIGH

WordPress Wallet System for WooCommerce plugin <= 2.7.5 - Broken Authentication vulnerability

Title source: cna
STIX 2.1

Description

Authentication Bypass Using an Alternate Path or Channel vulnerability in WP Swings Wallet System for WooCommerce allows Password Recovery Exploitation. This issue affects Wallet System for WooCommerce: from n/a through 2.7.5.

Scores

CVSS v3 7.1
EPSS 0.0021
EPSS Percentile 10.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-288
Status published
Products (1)
WP Swings/Wallet System for WooCommerce < 2.7.5
Published Jun 02, 2026
Tracked Since Jun 02, 2026