CVE-2026-93510
Received Received - Intake

Privilege Escalation in Points and Rewards for WooCommerce

Vulnerability report for CVE-2026-93510, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-23

Last updated on: 2026-09-23

Assigner: WPScan

Description

The Points and Rewards for WooCommerce WordPress plugin before 2.10.4 does not validate the claimed reward amount or restrict who can call its Win Wheel claim handler, allowing authenticated users, Subscriber and above, to credit their own account with an arbitrary and unlimited amount of loyalty points and, where a companion wallet Points and Rewards for WooCommerce WordPress plugin before 2.10.4 is active, wallet balance.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-23
Last Modified
2026-09-23
Generated
2026-09-23
AI Q&A
2026-09-23
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
points_and_rewards_for_woocommerce points_and_rewards_for_woocommerce to 2.10.4 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the Points and Rewards for WooCommerce plugin before version 2.10.4. It allows authenticated users with Subscriber-level access or higher to manipulate their loyalty points and wallet balance arbitrarily. The issue occurs because the plugin does not validate the claimed reward amount or restrict who can call its reward claim handler, enabling unauthorized point and balance adjustments.

Detection Guidance

Check if the Points and Rewards for WooCommerce plugin version is below 2.10.4. Use WordPress admin panel to inspect installed plugins or run: wp plugin list --name='points-and-rewards-for-woocommerce' in WP-CLI. If vulnerable, update immediately.

Impact Analysis

An attacker could exploit this to credit their account with an unlimited amount of loyalty points or wallet balance, potentially leading to financial loss for the store owner or unfair advantages in reward programs. The impact depends on the plugin's usage and configuration.

Compliance Impact

This vulnerability does not directly affect compliance with GDPR or HIPAA as it involves manipulation of loyalty points and wallet balances in a WordPress plugin. However, unauthorized changes to user data or financial balances could potentially violate data integrity principles under GDPR if personal data is involved. HIPAA is not applicable here as it pertains to healthcare data.

Mitigation Strategies

Update the Points and Rewards for WooCommerce plugin to version 2.10.4 or later. If immediate update is not possible, restrict Subscriber-level access to untrusted users or disable the plugin until patched.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-93510. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart