#VU121692 Missing Authorization in Wallet System For WooCommerce - CVE-2025-14450
Published: January 20, 2026
Wallet System For WooCommerce
MakeWebBetter
Description
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to missing authorization checks in the "change_wallet_fund_request_status_callback" function. A remote user can manipulate wallet withdrawal requests and arbitrarily increase their wallet balance or decrease other users' balances.