Authorization Flaw in Points and Rewards for WooCommerce by WordPress
CVE-2026-11782
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 30 July 2026
Badges
What is CVE-2026-11782?
The Points and Rewards for WooCommerce plugin does not implement necessary authorization checks on wallet and points update actions, which are exposed to unauthenticated users. This vulnerability allows attackers to modify or corrupt the wallet balance and loyalty points of any user without verification, potentially leading to financial losses or service disruption. To exploit this flaw, the companion Wallet System for WooCommerce Points and Rewards plugin must also be installed and active, thereby amplifying the risk for unprotected sites.
Affected Version(s)
Points and Rewards for WooCommerce 0 < 2.10.1
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved