Impact
The plugin fails to validate the reward amount and restrict access to the Win Wheel claim handler, allowing any authenticated user with Subscriber level or higher privileges to credit their own account with an arbitrary amount of loyalty points. When the companion Points and Rewards for WooCommerce Wallet plugin (version < 2.10.4) is also active, the same flaw lets the user inflate their wallet balance. This permits an attacker to influence account rewards or financial value without administrative privileges.
Affected Systems
Vulnerable versions are the Points and Rewards for WooCommerce WordPress plugin before 2.10.4 and the companion Points and Rewards for WooCommerce Wallet plugin before 2.10.4. The issue affects any WordPress installation that has either of these plugins installed on a version earlier than the stated release. The vendor is unknown according to the CNA.
Risk and Exploitability
The CVSS score of 4.3 classifies the flaw as medium severity. The EPSS score is below 1 %, indicating a low exploitation probability, and the vulnerability is not listed in CISA's KEV catalog. However, because the flaw requires only authentication at the Subscriber level, an attacker with a normal user account can exploit it by invoking the claim handler endpoint. Successful exploitation results in unauthorized accumulation of loyalty points and possibly wallet funds, potentially affecting loyalty program economics.
OpenCVE Enrichment