MyRewards <= 5.7.3 - Missing Authorization
medium
The MyRewards plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 5.7.3. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.
- CVSS:
- 4.3
- Affected:
- up to 5.7.3
- Fixed in:
- 5.7.4
- Disclosed:
- Apr 16, 2026
CVE-2026-40786 on NVD →
MyRewards – Loyalty Points and Rewards for WooCommerce – Reward orders, referrals, product reviews and more [woorewards] <= 5.6.0 (unfixed)
unknown
[en] The MyRewards – Loyalty Points and Rewards for WooCommerce plugin for WordPress is vulnerable to missing authorization in all versions up to, and including, 5.6.0. This is due to the plugin not properly verifying that a user is authorized to perform an action in the 'ajax' function. This makes it possible for auth...
- Affected:
- up to 5.6.0
- Fix:
- No patched version reported
- Disclosed:
- Feb 4, 2026
CVE-2025-15260 on NVD →
MyRewards – Loyalty Points and Rewards for WooCommerce <= 5.6.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Loyalty Rule Modification
medium
The MyRewards – Loyalty Points and Rewards for WooCommerce plugin for WordPress is vulnerable to missing authorization in all versions up to, and including, 5.6.1. This is due to the plugin not properly verifying that a user is authorized to perform an action in the 'ajax' function. This makes it possible for authentic...
- CVSS:
- 6.5
- Affected:
- up to 5.6.1
- Fixed in:
- 5.7.0
- Disclosed:
- Feb 3, 2026
CVE-2025-15260 on NVD →
MyRewards – Loyalty Points and Rewards for WooCommerce – Reward orders, referrals, product reviews and more [woorewards] <= 5.4.14 (unfixed)
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Long Watch Studio MyRewards allows Stored XSS. This issue affects MyRewards: from n/a through 5.4.13.1.
- Affected:
- up to 5.4.14
- Fix:
- No patched version reported
- Disclosed:
- Jul 4, 2025
CVE-2025-24757 on NVD →
MyRewards – Loyalty Points and Rewards for WooCommerce – Reward orders, referrals, product reviews and more [woorewards] < 5.3.1
unknown
[en] Missing Authorization vulnerability in Long Watch Studio MyRewards.This issue affects MyRewards: from n/a through 5.3.0.
- Affected:
- up to 5.3.1
- Fixed in:
- 5.3.1
- Disclosed:
- Apr 22, 2024
CVE-2024-32688 on NVD →
MyRewards <= 5.3.0 - Missing Authorization
medium
The MyRewards plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several functions in the /assets/lws-adminpanel/include/internal/ajax.php file in versions up to, and including, 5.3.0. This makes it possible for authenticated attackers, with subscriber-level access and above,...
- CVSS:
- 5.4
- Affected:
- up to 5.3.0
- Fixed in:
- 5.3.1
- Disclosed:
- Apr 17, 2024
CVE-2024-32688 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database