What the vulnerability does
01Description
Missing Authorization vulnerability in WP Swings Points and Rewards for WooCommerce.This issue affects Points and Rewards for WooCommerce: from n/a through 1.5.0.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
What the vulnerability does
Missing Authorization vulnerability in WP Swings Points and Rewards for WooCommerce.This issue affects Points and Rewards for WooCommerce: from n/a through 1.5.0.
Explanation of Vulnerability in Simple Terms
Points and Rewards for WooCommerce versions up to 1.5.0 lack proper authorization checks, allowing unauthenticated attackers to modify site data. An attacker can change reward points, alter customer records, or disable functionality without logging in. No user interaction is required. Update to a version newer than 1.5.0.
What an attacker can do
Modify reward points, customer data, or plugin settings without authentication.
Potential impact on your site
Attackers can corrupt customer reward data, disable the plugin, or manipulate WooCommerce records remotely.
Conditions required to exploit
Network access only; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities