Description
The Points and Rewards for WooCommerce WordPress plugin before 2.10.1 does not have authorisation checks in place on a wallet and points update action that is available to unauthenticated users, and does not verify that the requester owns the account being changed, allowing unauthenticated attackers to arbitrarily modify or corrupt (including driving it negative) the stored wallet balance and loyalty points of any user. Modifying the wallet balance additionally requires the companion Wallet System for WooCommerce Points and Rewards for WooCommerce WordPress plugin before 2.10.1 to be active.
Published: 2026-07-30
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an IDOR that allows unauthenticated users to modify the wallet balance and loyalty points of any customer. The plugin performs the update without verifying ownership of the target account, meaning an attacker can increase, decrease or nullify a user’s wallet balance and loyalty points. Because these values can represent store credit or reward points, altering them can result in financial loss or abuse for the merchant and its customers.

Affected Systems

Any installation of the Points and Rewards for WooCommerce plugin older than version 2.10.1 on a WordPress site is potentially affected. The issue also requires that the companion Wallet System for WooCommerce Points and Rewards for WooCommerce plugin is active and older than 2.10.1. Users who keep these plugins at versions below the stated thresholds are at risk.

Risk and Exploitability

The CVSS score of 5.9 reflects a moderate severity with an unauthenticated attack vector and impact limited to a single user account. The EPSS score of less than 1 % indicates a very low probability of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog. The exploit requires no special user privileges beyond sending a crafted HTTP request to the wallet or points update endpoint; the attacker must identify a valid user ID but does not need authentication. Once the endpoint is accessed, the attacker can set the wallet balance to any arbitrary value, including a negative figure, and adjust loyalty points in a similar manner.

Generated by OpenCVE AI on August 3, 2026 at 11:13 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Points and Rewards for WooCommerce plugin to version 2.10.1 or newer.
  • Update the companion Wallet System for WooCommerce plugin to a compatible version that implements authorization checks.
  • If an immediate update is not possible, restrict the wallet/points API endpoints so that only authenticated users with the appropriate roles can perform updates, or disable the updates entirely until the patch is applied.
  • After applying the patch, audit all user accounts for negative or suspicious wallet balances and loyalty point totals, and correct any anomalies.

Generated by OpenCVE AI on August 3, 2026 at 11:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 30 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 30 Jul 2026 13:45:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Wpswings
Wpswings points And Rewards For Woocommerce
Vendors & Products Wordpress
Wordpress wordpress
Wpswings
Wpswings points And Rewards For Woocommerce

Thu, 30 Jul 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Points and Rewards for WooCommerce WordPress plugin before 2.10.1 does not have authorisation checks in place on a wallet and points update action that is available to unauthenticated users, and does not verify that the requester owns the account being changed, allowing unauthenticated attackers to arbitrarily modify or corrupt (including driving it negative) the stored wallet balance and loyalty points of any user. Modifying the wallet balance additionally requires the companion Wallet System for WooCommerce Points and Rewards for WooCommerce WordPress plugin before 2.10.1 to be active.
Title Points and Rewards for WooCommerce < 2.10.1 - Unauthenticated Arbitrary User Wallet & Points Manipulation via IDOR
References

Subscriptions

Wordpress Wordpress
Wpswings Points And Rewards For Woocommerce
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-07-30T15:09:45.485Z

Reserved: 2026-06-09T12:33:00.570Z

Link: CVE-2026-11782

cve-icon Vulnrichment

Updated: 2026-07-30T15:09:23.077Z

cve-icon NVD

Status : Deferred

Published: 2026-07-30T06:24:58.037

Modified: 2026-07-30T16:45:00.353

Link: CVE-2026-11782

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T11:15:04Z

Weaknesses