CVE-2026-11782
Deferred Deferred - Pending Action

Unauthenticated Wallet Balance Modification in Points and Rewards for WooCommerce

Vulnerability report for CVE-2026-11782, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-30

Last updated on: 2026-07-30

Assigner: WPScan

Description

The Points and Rewards for WooCommerce WordPress plugin before 2.10.1 does not have authorisation checks in place on a wallet and points update action that is available to unauthenticated users, and does not verify that the requester owns the account being changed, allowing unauthenticated attackers to arbitrarily modify or corrupt (including driving it negative) the stored wallet balance and loyalty points of any user. Modifying the wallet balance additionally requires the companion Wallet System for WooCommerce Points and Rewards for WooCommerce WordPress plugin before 2.10.1 to be active.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-30
Last Modified
2026-07-30
Generated
2026-08-19
AI Q&A
2026-07-30
EPSS Evaluated
2026-08-18
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
woocommerce points_and_rewards to 2.10.1 (exc)
woocommerce wallet_system to 2.10.1 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-284 The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the Points and Rewards for WooCommerce plugin before version 2.10.1. It allows unauthenticated attackers to modify or corrupt wallet balances and loyalty points of any user due to missing authorization checks on an update action. Attackers can even drive these values negative. Exploiting this requires the companion Wallet System for WooCommerce plugin to be active.

Detection Guidance

Check if the Points and Rewards for WooCommerce plugin version is below 2.10.1. Inspect server logs for unusual wallet or points update requests targeting any user ID with negative values. Use WPScan to verify plugin versions: wpscan --url <your-site> --plugins-detection aggressive

Impact Analysis

Unauthenticated attackers could manipulate your wallet balance or loyalty points, potentially leading to financial loss or disruption of services. If you are a user of the affected plugin versions, your account data could be altered without your consent.

Compliance Impact

This vulnerability could lead to unauthorized data manipulation, potentially violating integrity and confidentiality requirements under GDPR and HIPAA. Affected organizations may face compliance breaches if user data is altered without proper authorization.

Mitigation Strategies

Update the Points and Rewards for WooCommerce plugin to version 2.10.1 or later. Disable the companion Wallet System for WooCommerce plugin if not required. Review and restrict user roles with access to wallet or points functions.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-11782. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart