Privilege Escalation in bLoyal: Loyalty & Promotions Plugin for WordPress
CVE-2026-15001

8.8HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
15 August 2026

What is CVE-2026-15001?

The bLoyal: Loyalty & Promotions plugin for WordPress contains a vulnerability that allows an authenticated attacker to escalate privileges. This occurs due to certain AJAX actions being improperly registered without necessary capability or nonce checks. Attackers with Subscriber-level access can exploit these actions to modify the API URL and related settings of the bLoyal Loyalty Engine. Consequently, they can trigger a REST route to fetch customer information from a malicious endpoint and gain unauthorized access to WordPress user accounts, including those of administrators.

Affected Version(s)

bLoyal: Loyalty & Promotions by bLoyal 0 <= 3.1.611.78

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

CHOIGYEONGMIN
.