Description
Missing Authorization vulnerability in Long Watch Studio MyRewards woorewards allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MyRewards: from n/a through <= 5.7.3.
Published: 2026-04-15
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation via Broken Access Control
Action: Patch immediately
AI Analysis

Impact

The vulnerability is a missing authorization check in the Long Watch Studio MyRewards plugin that allows an attacker to bypass intended access controls. This flaw can enable unauthorized users to perform privileged actions through the plugin’s interface or web endpoints, effectively escalating privileges within the WordPress site. The weakness falls under the privilege escalation category.

Affected Systems

The affected product is the WordPress plugin MyRewards from Long Watch Studio (also known as woorewards), with all releases through version 5.7.3 vulnerable. Any WordPress installation that has this plugin installed and uses one of those versions is at risk, regardless of the WordPress core version.

Risk and Exploitability

The CVSS score is 4.3, indicating a moderate impact. The EPSS score is <1%, showing a low exploitation probability, and the issue is not listed in CISA’s KEV catalog. However, because the flaw is an access control bypass, it can be leveraged by anyone who can access the plugin’s web interface, making the potential impact significant if the site is publicly reachable or if an attacker can obtain basic user credentials. The most likely attack vector is through crafted HTTP requests to the plugin’s administrative endpoints, requiring only web access to the vulnerable WordPress instance.

Generated by OpenCVE AI on April 17, 2026 at 07:56 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the MyRewards plugin to the latest release (>=5.7.4) as soon as a vendor patch is available.
  • If an update is not immediately possible, restrict access to the plugin’s administrative URLs by adding a capability check in the plugin code or using a .htaccess rule that allows only users with the "manage_options" capability to reach those pages.
  • Monitor the site for suspicious activity and ensure that the plugin cannot be accessed by anonymous or non-admin users; consider disabling the plugin entirely if it is not critical.

Generated by OpenCVE AI on April 17, 2026 at 07:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 29 Apr 2026 10:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Thu, 16 Apr 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 15 Apr 2026 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Long Watch Studio
Long Watch Studio myrewards
Wordpress
Wordpress wordpress
Vendors & Products Long Watch Studio
Long Watch Studio myrewards
Wordpress
Wordpress wordpress

Wed, 15 Apr 2026 10:45:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in Long Watch Studio MyRewards woorewards allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MyRewards: from n/a through <= 5.7.3.
Title WordPress MyRewards plugin <= 5.7.3 - Broken Access Control vulnerability
Weaknesses CWE-862
References

Subscriptions

Long Watch Studio Myrewards
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-29T09:52:04.932Z

Reserved: 2026-04-15T09:20:42.117Z

Link: CVE-2026-40786

cve-icon Vulnrichment

Updated: 2026-04-16T14:18:20.373Z

cve-icon NVD

Status : Deferred

Published: 2026-04-15T11:16:37.153

Modified: 2026-04-29T10:17:46.200

Link: CVE-2026-40786

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-17T08:00:11Z

Weaknesses