Executive brief
Points and Rewards for WooCommerce is a WordPress plugin that manages customer loyalty programs through earned and redeemable points. The plugin fails to validate reward amounts or enforce access controls, allowing authenticated users with minimal privileges to award themselves unlimited loyalty points and wallet balances. An attacker could exploit this to fraudulently credit their account with points worth real money or merchandise.
Technical details
The vulnerability exists in the Win Wheel claim handler which lacks input validation and proper authorization checks. Authenticated users with Subscriber role and above can call the assign_claim_points function without restriction to award themselves arbitrary amounts of points. The missing authorization (CWE-862) combined with lack of input validation allows privilege escalation from Subscriber to self-enrichment of loyalty accounts.
Affected products
- Wordpress.org Points and Rewards for WooCommerce before 2.10.4
Timeline
- 2026-09-21: disclosed
- 2026-09-23: patched: Version 2.10.4 released