Impact
The vulnerability is an IDOR that allows unauthenticated users to modify the wallet balance and loyalty points of any customer. The plugin performs the update without verifying ownership of the target account, meaning an attacker can increase, decrease or nullify a user’s wallet balance and loyalty points. Because these values can represent store credit or reward points, altering them can result in financial loss or abuse for the merchant and its customers.
Affected Systems
Any installation of the Points and Rewards for WooCommerce plugin older than version 2.10.1 on a WordPress site is potentially affected. The issue also requires that the companion Wallet System for WooCommerce Points and Rewards for WooCommerce plugin is active and older than 2.10.1. Users who keep these plugins at versions below the stated thresholds are at risk.
Risk and Exploitability
The CVSS score of 5.9 reflects a moderate severity with an unauthenticated attack vector and impact limited to a single user account. The EPSS score of less than 1 % indicates a very low probability of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog. The exploit requires no special user privileges beyond sending a crafted HTTP request to the wallet or points update endpoint; the attacker must identify a valid user ID but does not need authentication. Once the endpoint is accessed, the attacker can set the wallet balance to any arbitrary value, including a negative figure, and adjust loyalty points in a similar manner.
OpenCVE Enrichment