plugin

Woorewards Vulnerabilities

6 known security issues reported for the Woorewards WordPress plugin. Most recent disclosed Apr 16, 2026.

3 medium

Running Woorewards on your site? Check whether your installed version is affected.

Scan your site free

MyRewards <= 5.7.3 - Missing Authorization

medium

The MyRewards plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 5.7.3. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.

CVSS:
4.3
Affected:
up to 5.7.3
Fixed in:
5.7.4
Disclosed:
Apr 16, 2026

CVE-2026-40786 on NVD →

MyRewards &#8211; Loyalty Points and Rewards for WooCommerce &#8211; Reward orders, referrals, product reviews and more [woorewards] <= 5.6.0 (unfixed)

unknown

[en] The MyRewards – Loyalty Points and Rewards for WooCommerce plugin for WordPress is vulnerable to missing authorization in all versions up to, and including, 5.6.0. This is due to the plugin not properly verifying that a user is authorized to perform an action in the 'ajax' function. This makes it possible for auth...

Affected:
up to 5.6.0
Fix:
No patched version reported
Disclosed:
Feb 4, 2026

CVE-2025-15260 on NVD →

MyRewards – Loyalty Points and Rewards for WooCommerce <= 5.6.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Loyalty Rule Modification

medium

The MyRewards – Loyalty Points and Rewards for WooCommerce plugin for WordPress is vulnerable to missing authorization in all versions up to, and including, 5.6.1. This is due to the plugin not properly verifying that a user is authorized to perform an action in the 'ajax' function. This makes it possible for authentic...

CVSS:
6.5
Affected:
up to 5.6.1
Fixed in:
5.7.0
Disclosed:
Feb 3, 2026

CVE-2025-15260 on NVD →

MyRewards &#8211; Loyalty Points and Rewards for WooCommerce &#8211; Reward orders, referrals, product reviews and more [woorewards] <= 5.4.14 (unfixed)

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Long Watch Studio MyRewards allows Stored XSS. This issue affects MyRewards: from n/a through 5.4.13.1.

Affected:
up to 5.4.14
Fix:
No patched version reported
Disclosed:
Jul 4, 2025

CVE-2025-24757 on NVD →

MyRewards &#8211; Loyalty Points and Rewards for WooCommerce &#8211; Reward orders, referrals, product reviews and more [woorewards] < 5.3.1

unknown

[en] Missing Authorization vulnerability in Long Watch Studio MyRewards.This issue affects MyRewards: from n/a through 5.3.0.

Affected:
up to 5.3.1
Fixed in:
5.3.1
Disclosed:
Apr 22, 2024

CVE-2024-32688 on NVD →

MyRewards <= 5.3.0 - Missing Authorization

medium

The MyRewards plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several functions in the /assets/lws-adminpanel/include/internal/ajax.php file in versions up to, and including, 5.3.0. This makes it possible for authenticated attackers, with subscriber-level access and above,...

CVSS:
5.4
Affected:
up to 5.3.0
Fixed in:
5.3.1
Disclosed:
Apr 17, 2024

CVE-2024-32688 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database