Access violation vulnerability in MyRewards – Loyalty Points and Rewards for WooCommerce – Reward orders, referrals, product reviews and more 5.6.0

The MyRewards plugin for WordPress allows users to earn loyalty points and rewards on WooCommerce. However, it has a security vulnerability in all versions up to 5.6.0. This means that the plugin does not properly check if a user has permission to do something in the ‘ajax’ function. As a result, attackers with subscriber level access or higher can change, add, or delete rules for earning loyalty points. They can even change the point multipliers to any value they want.

Detected in:

MyRewards fixed vulnerable versions:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.