What the vulnerability does
01Description
Missing Authorization vulnerability in WP Swings Points and Rewards for WooCommerce.This issue affects Points and Rewards for WooCommerce: from n/a through 1.5.0.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
What the vulnerability does
Missing Authorization vulnerability in WP Swings Points and Rewards for WooCommerce.This issue affects Points and Rewards for WooCommerce: from n/a through 1.5.0.
Explanation of Vulnerability in Simple Terms
Points and Rewards for WooCommerce versions up to 1.5.0 lack proper authorization checks, allowing authenticated users to modify or disable reward functionality without proper permission. An attacker with a low-privilege account can alter site rewards settings or availability. Update to a version newer than 1.5.0 to resolve this issue.
What an attacker can do
Modify or disable reward settings and functionality on the WooCommerce site.
Potential impact on your site
Reward program integrity compromised; low-privilege users can alter points, rewards, or program settings.
Conditions required to exploit
Attacker must have a low-privilege user account on the site (e.g., customer or subscriber role).
Key dates
External resources
Related vulnerabilities