What is CVE-2026-15001?
CVE-2026-15001 is a Privilege Escalation vulnerability in the bLoyal: Loyalty & Promotions by bLoyal WordPress plugin. It exists due to the 'save_bloyal_configuration_data' and 'save_bloyal_accesskeyverification_data' AJAX actions being registered without proper capability checks. Site administrators should immediately update the plugin to the latest version or temporarily deactivate it.
Azərbaycanca: CVE-2026-15001, bLoyal: Loyalty & Promotions by bLoyal WordPress plaginində imtiyaz artırma (Privilege Escalation) zəifliyidir. 'save_bloyal_configuration_data' və 'save_bloyal_accesskeyverification_data' AJAX əməliyyatlarının yetərli icazə yoxlaması olmadan qeydiyyatdan keçməsi səbəbindən yaranır. Sayt adminləri plagini dərhal ən son versiyaya yeniləməli və ya müvəqqəti olaraq deaktiv etməlidir.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
What causes the CVE-2026-15001 vulnerability in the bLoyal WordPress plugin?
The vulnerability exists because the 'save_bloyal_configuration_data' and 'save_bloyal_accesskeyverification_data' AJAX actions are registered without proper capability checks.
What should site administrators do to protect against CVE-2026-15001?
Site administrators should immediately update the bLoyal plugin to the latest version or temporarily deactivate it.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.