Privilege Escalation in bLoyal: Loyalty & Promotions Plugin for WordPress
CVE-2026-15001
8.8HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 15 August 2026
What is CVE-2026-15001?
The bLoyal: Loyalty & Promotions plugin for WordPress contains a vulnerability that allows an authenticated attacker to escalate privileges. This occurs due to certain AJAX actions being improperly registered without necessary capability or nonce checks. Attackers with Subscriber-level access can exploit these actions to modify the API URL and related settings of the bLoyal Loyalty Engine. Consequently, they can trigger a REST route to fetch customer information from a malicious endpoint and gain unauthorized access to WordPress user accounts, including those of administrators.
Affected Version(s)
bLoyal: Loyalty & Promotions by bLoyal 0 <= 3.1.611.78