CVE-2026-11782: Points and Rewards for WooCommerce < 2.10.1 - Unauthenticated Arbitrary User Wallet & Points Manipulation via IDOR
The Points and Rewards for WooCommerce WordPress plugin before 2.10.1 does not have authorisation checks in place on a wallet and points update action that is available to unauthenticated users, and does not verify that the requester owns the account being changed, allowing unauthenticated attackers to arbitrarily modify or corrupt (including driving it negative) the stored wallet balance and loyalty points of any user. Modifying the wallet balance additionally requires the companion Wallet System for WooCommerce Points and Rewards for WooCommerce WordPress plugin before 2.10.1 to be active.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Points and Rewards for WooCommerce WordPress pluginto a version that resolves this vulnerability.Fixed in 2.10.1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-11782?
CVE-2026-11782 has a medium severity rating of 5.9 based on the CVSS 3.1 scoring system.
How do I fix CVE-2026-11782?
To fix CVE-2026-11782, update the Points and Rewards for WooCommerce plugin to version 2.10.1 or later.
What exploit does CVE-2026-11782 enable?
CVE-2026-11782 enables unauthenticated attackers to manipulate user wallet and points without proper authorization.
Which versions are affected by CVE-2026-11782?
CVE-2026-11782 affects all versions of the Points and Rewards for WooCommerce plugin prior to 2.10.1.
What type of vulnerability is CVE-2026-11782?
CVE-2026-11782 is classified as an unauthenticated arbitrary user wallet and points manipulation vulnerability due to insufficient authorization checks.