PT-2026-63572 · Fantasticplugins · Points/Rewards For Woocommerce
CVE-2026-7534
·
Published
2026-07-23
·
Updated
2026-07-23
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N |
The SUMO Reward Points plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting via the REST API endpoint
/wp-json/wc-srp/v1/earning in versions up to, and including, 32.7.0. This is due to the user has cap filter in the SRP REST Earning Controller class unconditionally granting the custom rs earning read capability to all users — including unauthenticated visitors — combined with missing sanitization of the reason parameter in the create items() function and missing output escaping in the column default() method of SRP Master Log. This makes it possible for unauthenticated attackers to inject arbitrary web scripts into the reward points log that will execute whenever an administrator accesses the Master Log or User Reward Points admin pages.Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Points/Rewards For Woocommerce