The Wallet for WooCommerce WordPress plugin before 1.6.10 does not verify the amount actually collected for a wallet top-up before crediting the wallet, allowing customers to top up their wallet balance for less than its value.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
The Wallet for WooCommerce plugin before version 1.6.10 contains a critical payment validation flaw (CVE-2026-16538, CVSS 9.1) that allows customers to credit their wallet accounts with arbitrary amounts regardless of actual payment received. This vulnerability stems from insufficient input validation and authorization checks (CWE-284) on wallet top-up transactions. WooCommerce store operators are directly affected, as attackers can artificially inflate wallet balances without making legitimate payments, leading to immediate financial loss, inventory depletion through fraudulent purchases, and potential cascading business disruption. The vulnerability is particularly dangerous because it targets the payment processing logic at its core—a trusted financial function that most merchants assume is secure by default.
While this CVE lacks specific MITRE ATT&CK technique mappings, Casky's security skills powered by Claude's extended reasoning capabilities would detect the underlying attack patterns by analyzing transaction logs for anomalies in the T1078 (Valid Accounts) and T1190 (Exploit Public-Facing Application) threat space. Practitioners using Casky would identify suspicious indicators such as wallet credit transactions where submitted payment amounts deviate significantly from credited values, multiple top-up attempts from the same account with progressively larger discrepancies, or transactions completing without corresponding payment gateway confirmation records. The platform's 754 mapped security skills would flag improper payment state transitions, missing cryptographic validation tokens, and authorization bypass patterns—enabling defenders to spot both active exploitation and misconfigurations before financial impact occurs. Organizations should immediately patch to version 1.6.10+ and audit wallet transaction histories for fraudulent credits.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-16538. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation