The Wallet for WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.6.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to enumerate the login name, email address, and user ID of all WordPress accounts — including administrators — by submitting arbitrary search terms to the AJAX handler. The required 'search-user' nonce is localized into the wallet_param object on the standard WooCommerce My Account page, which is accessible to any authenticated user, making it trivially obtainable by a Subscriber.
We have discovered 1,010 live websites that are affected by CVE-2026-12103.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 1,010 live websites (97% of Woo Wallet install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 44 versions ( 96% of all versions) |
| 244 websites | |
| 253 websites | |
| 69 websites | |
| 65 websites | |
| 46 websites | |
| 44 websites | |
| 23 websites | |
| 22 websites | |
| 21 websites | |
| 18 websites |
| .com | 532 websites |
| .net | 20 websites |
| .com.br | 20 websites |
| .ru | 19 websites |
| .co.uk | 17 websites |
| .it | 15 websites |
| .fr | 14 websites |
| .nl | 10 websites |
| .org | 10 websites |
| .de | 9 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ******.global | ***,*** | ||
| ***********.com | ***,*** | ||
| *******.**.ke | ***,*** | ||
| ******.ir | ***,*** | ||
| **********.com | ***,*** | ||
| *************.ir | ***,*** | ||
| ****************.***.uk | ***,*** | ||
| ****.*******.ir | ***,*** | ||
| ***********.ir | ***,*** | ||
| *******.com | ***,*** |
FAQ