Authorization Flaw in MyRewards Loyalty Points Plugin for WooCommerce
CVE-2025-15260

6.5MEDIUM

Key Information:

Vendor

WordPress

Status
Vendor
CVE Published:
4 February 2026

Badges

πŸ‘Ύ Exploit Exists🟑 Public PoC

What is CVE-2025-15260?

The MyRewards – Loyalty Points and Rewards for WooCommerce plugin for WordPress has a significant flaw that lacks proper user authorization checks in its 'ajax' function. This insufficiency allows authenticated users with subscriber access or higher to make unauthorized changes to loyalty program configurations. They can modify, add, or delete earning rules and even adjust point multipliers to unforeseen values, potentially compromising the integrity of the loyalty program.

Affected Version(s)

MyRewards 0 <= 5.6.1

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • 🟑

    Public PoC available

  • πŸ‘Ύ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Tharadol Suksamran
.