Junglewise Threat Intelligence

CVE-2026-93510: Points and Rewards for WooCommerce arbitrary points manipulation

CVE-2026-93510 · Severity: medium · CVSS 4.3 · Published 2026-09-23

Vendors: WordPress.org.

Executive brief

Points and Rewards for WooCommerce is a WordPress plugin that manages customer loyalty programs through earned and redeemable points. The plugin fails to validate reward amounts or enforce access controls, allowing authenticated users with minimal privileges to award themselves unlimited loyalty points and wallet balances. An attacker could exploit this to fraudulently credit their account with points worth real money or merchandise.

Technical details

The vulnerability exists in the Win Wheel claim handler which lacks input validation and proper authorization checks. Authenticated users with Subscriber role and above can call the assign_claim_points function without restriction to award themselves arbitrary amounts of points. The missing authorization (CWE-862) combined with lack of input validation allows privilege escalation from Subscriber to self-enrichment of loyalty accounts.

Affected products

  • Wordpress.org Points and Rewards for WooCommerce before 2.10.4

Timeline

  • 2026-09-21: disclosed
  • 2026-09-23: patched: Version 2.10.4 released

References