Skip to main content
Vulnerability Database/CVE-2026-93510

CVE-2026-93510: WooCommerce Points Plugin Privilege Escalation

CVE-2026-93510 is a privilege escalation vulnerability in the Points and Rewards for WooCommerce plugin that lets authenticated users award themselves unlimited loyalty points and wallet balance. This article covers technical details, affected versions, security impact, and mitigation strategies.

Published:

CVE-2026-93510 Overview

CVE-2026-93510 affects the Points and Rewards for WooCommerce WordPress plugin in versions before 2.10.4. The plugin fails to validate the claimed reward amount and does not restrict access to its Win Wheel claim handler. Any authenticated user with Subscriber role or higher can credit their own account with arbitrary and unlimited loyalty points. When a companion wallet plugin is active, attackers can also inflate their wallet balance. The flaw is tracked as a Missing Authorization weakness [CWE-862].

Critical Impact

Authenticated users at Subscriber level or above can grant themselves unlimited loyalty points and wallet balance, resulting in financial loss for merchants.

Affected Products

  • Points and Rewards for WooCommerce WordPress plugin versions before 2.10.4
  • Companion wallet integrations tied to the same plugin family
  • WooCommerce storefronts that expose the Win Wheel claim handler to Subscriber accounts

Discovery Timeline

  • 2026-09-23 - CVE-2026-93510 published to the National Vulnerability Database (NVD)
  • 2026-09-23 - Last updated in NVD database

Technical Details for CVE-2026-93510

Vulnerability Analysis

The vulnerability resides in the Win Wheel claim handler exposed by the Points and Rewards for WooCommerce plugin. The handler accepts a reward amount from the client and writes it directly to the user's points balance. It performs neither server-side validation of the claimed value nor a capability check on the caller. Any user session holding at least the Subscriber role can invoke the endpoint and specify an arbitrary integer.

When a companion wallet plugin from the same product family is installed, the credited points synchronize with the wallet balance. This lets attackers convert fabricated points into store credit usable at checkout. The impact scales with each request because there is no rate limit or once-per-spin enforcement on the server side.

Root Cause

The root cause is Missing Authorization [CWE-862] combined with absent input validation. The claim handler trusts client-supplied data for both identity intent and reward magnitude. Server-side logic should recompute the reward from a trusted spin result and confirm the caller owns the current spin session.

Attack Vector

Exploitation requires network access to the WordPress site and valid credentials for any account at Subscriber level or higher. WordPress installations that allow self-registration expose the flaw to anonymous internet users who register an account. The attacker submits a crafted request to the Win Wheel claim endpoint with an inflated reward value and repeats the request to accumulate balance.

No verified proof-of-concept code has been published. Refer to the WPScan Vulnerability Report for advisory-level details.

Detection Methods for CVE-2026-93510

Indicators of Compromise

  • Repeated POST requests from a single authenticated Subscriber account to the Win Wheel claim handler within a short window
  • User accounts with points balances or wallet balances that exceed values reachable through normal Win Wheel play
  • Order records that use large wallet credit redemptions from newly registered Subscriber accounts
  • Audit log entries showing points adjustments without a corresponding administrator action

Detection Strategies

  • Query the WordPress database for wp_usermeta entries tied to the plugin's points key and flag values exceeding normal earning ceilings
  • Correlate WooCommerce order logs with wallet credit application events sourced from Subscriber-role users
  • Alert on high-frequency AJAX or REST calls to the plugin's claim endpoint from a single session cookie

Monitoring Recommendations

  • Enable WordPress action logging for user meta changes and plugin claim endpoints
  • Ingest webserver access logs into a SIEM and baseline normal request rates for the Win Wheel endpoint
  • Monitor new Subscriber registrations followed by immediate wallet redemption activity

How to Mitigate CVE-2026-93510

Immediate Actions Required

  • Update the Points and Rewards for WooCommerce plugin to version 2.10.4 or later on all WooCommerce sites
  • Audit user points and wallet balances for anomalous credits and reverse fraudulent adjustments
  • Temporarily disable open user registration until the patch is confirmed in place

Patch Information

The vendor addressed the flaw in Points and Rewards for WooCommerce version 2.10.4. Administrators should upgrade through the WordPress plugin manager or WP-CLI and verify the installed version matches or exceeds 2.10.4. See the WPScan Vulnerability Report for the authoritative advisory.

Workarounds

  • Deactivate the Points and Rewards for WooCommerce plugin until the upgrade is applied
  • Block access to the Win Wheel claim endpoint at the web application firewall for non-privileged roles
  • Restrict new account creation and require administrator approval for Subscriber-level registrations
bash
# Upgrade the plugin using WP-CLI
wp plugin update woo-points-rewards --version=2.10.4
wp plugin list --name=woo-points-rewards --fields=name,version,status

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.