CVE-2025-15260
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-15260 is a missing authorization vulnerability in the MyRewards – Loyalty Points and Rewards for WooCommerce plugin for WordPress. It affects all versions up to and including 5.6.1 (ENISA data references ≤5.6.0), allowing authenticated attackers with subscriber-level access or above to manipulate loyalty program earning rules via unprotected AJAX calls. The vulnerability was published on February 4, 2026, and assigned a CVSS v3.1 base score of 6.5 (Medium) (Wordfence, Red Hat CVE).

Technical details

The root cause is CWE-862 (Missing Authorization): the plugin's ajax function does not properly verify whether the requesting user has the necessary privileges to perform administrative actions on loyalty program rules (Wordfence). The vulnerable code path is located in assets/lws-adminpanel/include/internal/editlistcontroler.php at line 76, where AJAX-triggered operations lack capability checks (ENISA EUVD). An attacker only needs a valid WordPress account (subscriber or higher) and network access to the target site to exploit this flaw — no special configuration or interaction from an administrator is required.

Impact

Successful exploitation allows authenticated low-privileged users to modify, add, or delete loyalty program earning rules, including setting point multipliers to arbitrary values. This can result in significant financial loss for e-commerce operators by enabling attackers to fraudulently accumulate reward points, redeem them for discounts or products, or disrupt the integrity of the loyalty program entirely. Confidentiality and availability are not directly impacted, but the integrity of business-critical reward data is fully compromised (Wordfence).

Exploitability

A proof-of-concept exploit has been published on GitHub (github.com/d3kc4rt1/CVE-2025-15260) and referenced on Sploitus (PacketStorm:218678), indicating public weaponization (Feedly). No confirmed in-the-wild exploitation or threat actor attribution has been reported at this time. The EPSS score is approximately 0.026% (0.000260), reflecting low but non-zero exploitation probability. This CVE is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the MyRewards – Loyalty Points and Rewards for WooCommerce plugin (version ≤5.6.1) using tools like WPScan or by checking /wp-content/plugins/woorewards/ paths.
  2. Obtain low-privileged account: Register or use an existing subscriber-level (or higher) WordPress account on the target site.
  3. Identify the vulnerable AJAX endpoint: Locate the WordPress AJAX handler (typically wp-admin/admin-ajax.php) and identify the action parameter associated with the plugin's editlistcontroler.php functionality.
  4. Craft malicious AJAX request: Send an authenticated POST request to wp-admin/admin-ajax.php with the appropriate action and parameters to modify loyalty earning rules (e.g., set point multipliers to an extremely high value), bypassing the missing authorization check.
  5. Abuse manipulated rules: Use a customer account to make purchases or perform actions that trigger the manipulated earning rules, accumulating fraudulent loyalty points for financial gain or disruption (Wordfence, GitHub PoC).

Indicators of compromise

  • Network: Unusual POST requests to wp-admin/admin-ajax.php from subscriber-level user sessions, particularly with action parameters related to loyalty rule editing or point multiplier updates.
  • Logs: WordPress access logs showing repeated AJAX calls to loyalty rule management endpoints from non-administrative user accounts; unexpected changes to WooCommerce loyalty program configurations in audit logs.
  • Application: Sudden, unexplained changes to point multiplier values or earning rules in the MyRewards plugin admin panel; abnormal accumulation of loyalty points by low-privileged user accounts.
  • Database: Unexpected modifications to loyalty program rule records in the WordPress database (wp_options or plugin-specific tables) outside of normal administrative activity.

Mitigation and workarounds

Site administrators should update the MyRewards – Loyalty Points and Rewards for WooCommerce plugin to version 5.6.1 or later, which addresses the missing authorization check (Wordfence). As an interim measure, consider restricting subscriber-level user registrations or temporarily disabling the plugin until the patch is applied. Review loyalty program rules and point balances for any unauthorized modifications following the patch.

Community reactions

Wordfence included this vulnerability in their weekly WordPress vulnerability report for February 2–8, 2026, highlighting it as part of a broader set of plugin authorization issues (Wordfence Blog). No significant additional vendor statements or notable researcher commentary beyond the Wordfence disclosure have been identified.

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-92541HIGH7.2
  • import-users-from-csv-with-meta
NoYesSep 20, 2026
CVE-2026-92540HIGH7.2
  • import-users-from-csv-with-meta
NoYesSep 20, 2026
CVE-2026-86785MEDIUM5.3
  • woo-to-facebook-shop
NoNoSep 20, 2026
CVE-2026-92965LOW3.7
  • tiktok-for-business
NoYesSep 20, 2026
CVE-2026-92423LOW2.7
  • meow-gallery
NoYesSep 20, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management