CVE-2026-12103

Wallet for WooCommerce <= 1.6.4 - Missing Authorization to Authenticated (Subscriber+) User/Email Enumeration via terawallet_export_user_search AJAX Action

The Wallet for WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.6.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to enumerate the login name, email address, and user ID of all WordPress accounts — including administrators — by submitting arbitrary search terms to the AJAX handler. The required 'search-user' nonce is localized into the wallet_param object on the standard WooCommerce My Account page, which is accessible to any authenticated user, making it trivially obtainable by a Subscriber.


We have discovered 1,010 live websites that are affected by CVE-2026-12103.

Run a Free Instant Scan




Affected Software

Product  Woo Wallet
Category Wordpress Plugins
Vulnerable Domains1,010 live websites (97% of Woo Wallet install base)
Vulnerable Versions
  • from 0 through 1.6.4
Vulnerable Versions Count44 versions ( 96% of all versions)


Common Weakness Enumeration

CWE-862 Missing Authorization



Details

  • Published - Jul 11, 2026
  • Updated - Jul 13, 2026

Credits

  • Mitchell (finder)

Website Distribution by Country

Number of websites using CVE-2026-12103
United States244 websites



Iran253 websites
India69 websites
Germany65 websites
GB46 websites
France44 websites
Cyprus23 websites
Russia22 websites
Italy21 websites
South Africa18 websites

Website Distribution by TLD

Number of websites using CVE-2026-12103
.com532 websites
.net20 websites
.com.br20 websites
.ru19 websites
.co.uk17 websites
.it15 websites
.fr14 websites
.nl10 websites
.org10 websites
.de9 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-12103

Top websites that are affected by CVE-2026-12103. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
******.global United States***,***
***********.com United States***,***
*******.**.ke Germany***,***
******.ir Iran***,***
**********.com Germany***,***
*************.ir Iran***,***
****************.***.uk GB***,***
****.*******.ir Iran***,***
***********.ir Iran***,***
*******.com United States***,***
See full domain list

FAQ

CVE-2026-12103 is Missing Authorization in Woo Wallet
A total of 1,010 websites have been identified as vulnerable to CVE-2026-12103, based on global website indexing conducted by WebTechSurvey.
The Woo Wallet is affected by the CVE-2026-12103 vulnerability.
Woo Wallet versions up to and including 1.6.4 are vulnerable to CVE-2026-12103.

References