Authorization Flaw in MyRewards Loyalty Points Plugin for WooCommerce
CVE-2025-15260
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 4 February 2026
What is CVE-2025-15260?
The MyRewards β Loyalty Points and Rewards for WooCommerce plugin for WordPress has a significant flaw that lacks proper user authorization checks in its 'ajax' function. This insufficiency allows authenticated users with subscriber access or higher to make unauthorized changes to loyalty program configurations. They can modify, add, or delete earning rules and even adjust point multipliers to unforeseen values, potentially compromising the integrity of the loyalty program.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
MyRewards β Loyalty Points and Rewards for WooCommerce β Reward orders, referrals, product reviews and more * <= 5.6.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved