
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-15260 is a missing authorization vulnerability in the MyRewards – Loyalty Points and Rewards for WooCommerce plugin for WordPress. It affects all versions up to and including 5.6.1 (ENISA data references ≤5.6.0), allowing authenticated attackers with subscriber-level access or above to manipulate loyalty program earning rules via unprotected AJAX calls. The vulnerability was published on February 4, 2026, and assigned a CVSS v3.1 base score of 6.5 (Medium) (Wordfence, Red Hat CVE).
The root cause is CWE-862 (Missing Authorization): the plugin's ajax function does not properly verify whether the requesting user has the necessary privileges to perform administrative actions on loyalty program rules (Wordfence). The vulnerable code path is located in assets/lws-adminpanel/include/internal/editlistcontroler.php at line 76, where AJAX-triggered operations lack capability checks (ENISA EUVD). An attacker only needs a valid WordPress account (subscriber or higher) and network access to the target site to exploit this flaw — no special configuration or interaction from an administrator is required.
Successful exploitation allows authenticated low-privileged users to modify, add, or delete loyalty program earning rules, including setting point multipliers to arbitrary values. This can result in significant financial loss for e-commerce operators by enabling attackers to fraudulently accumulate reward points, redeem them for discounts or products, or disrupt the integrity of the loyalty program entirely. Confidentiality and availability are not directly impacted, but the integrity of business-critical reward data is fully compromised (Wordfence).
A proof-of-concept exploit has been published on GitHub (github.com/d3kc4rt1/CVE-2025-15260) and referenced on Sploitus (PacketStorm:218678), indicating public weaponization (Feedly). No confirmed in-the-wild exploitation or threat actor attribution has been reported at this time. The EPSS score is approximately 0.026% (0.000260), reflecting low but non-zero exploitation probability. This CVE is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.
/wp-content/plugins/woorewards/ paths.wp-admin/admin-ajax.php) and identify the action parameter associated with the plugin's editlistcontroler.php functionality.wp-admin/admin-ajax.php with the appropriate action and parameters to modify loyalty earning rules (e.g., set point multipliers to an extremely high value), bypassing the missing authorization check.wp-admin/admin-ajax.php from subscriber-level user sessions, particularly with action parameters related to loyalty rule editing or point multiplier updates.wp_options or plugin-specific tables) outside of normal administrative activity.Site administrators should update the MyRewards – Loyalty Points and Rewards for WooCommerce plugin to version 5.6.1 or later, which addresses the missing authorization check (Wordfence). As an interim measure, consider restricting subscriber-level user registrations or temporarily disabling the plugin until the patch is applied. Review loyalty program rules and point balances for any unauthorized modifications following the patch.
Wordfence included this vulnerability in their weekly WordPress vulnerability report for February 2–8, 2026, highlighting it as part of a broader set of plugin authorization issues (Wordfence Blog). No significant additional vendor statements or notable researcher commentary beyond the Wordfence disclosure have been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."