Authorization Flaw in Points and Rewards for WooCommerce by WordPress
CVE-2026-11782

5.9MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
30 July 2026

Badges

๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC

What is CVE-2026-11782?

The Points and Rewards for WooCommerce plugin does not implement necessary authorization checks on wallet and points update actions, which are exposed to unauthenticated users. This vulnerability allows attackers to modify or corrupt the wallet balance and loyalty points of any user without verification, potentially leading to financial losses or service disruption. To exploit this flaw, the companion Wallet System for WooCommerce Points and Rewards plugin must also be installed and active, thereby amplifying the risk for unprotected sites.

Affected Version(s)

Points and Rewards for WooCommerce 0 < 2.10.1

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Sanjorn Keeratirungsan
WPScan
.