What is CVE-2026-11782?
CVE-2026-11782 is a vulnerability in the 'Points and Rewards for WooCommerce' WordPress plugin before version 2.10.1. It allows unauthenticated attackers to update wallets and points due to missing authorization checks on the relevant action. To mitigate this, users should immediately update the plugin to the latest version.
Azərbaycanca: CVE-2026-11782, WooCommerce üçün 'Points and Rewards' WordPress plagininin 2.10.1-dən əvvəlki versiyalarında aşkar edilmiş zəiflikdir. Bu boşluq autentifikasiya olunmamış istifadəçilərə pul kisəsi və bonus xallarını yeniləməyə imkan verir, çünki plagin icazə yoxlamalarını düzgün həyata keçirmir. Təsirə məruz qalmamaq üçün plagini dərhal ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862; shared vendor: WooCommerce
FAQ2
What is the name of the plugin affected by CVE-2026-11782?
The vulnerability was found in the 'Points and Rewards for WooCommerce' WordPress plugin.
What version should the plugin be updated to in order to avoid this vulnerability?
To mitigate the risk, you should immediately update the plugin to version 2.10.1 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.