What is CVE-2026-7534?
CVE-2026-7534 is an Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability in the SUMO Reward Points WordPress plugin (version ≤ 32.7.0) via the `/wp-json/wc-srp/v1/earning` REST API endpoint. It stems from insufficient validation in the `user_has_cap` filter within the `SRP_REST_Earning_Controller` class. Immediate update to the latest plugin version is required.
Azərbaycanca: CVE-2026-7534, SUMO Reward Points WordPress pluginində (versiya ≤ 32.7.0) `/wp-json/wc-srp/v1/earning` REST API endpoint-i vasitəsilə autentifikasiya olunmadan saxlanılan Stored Cross-Site Scripting (XSS) zəifliyidir. Bu, `SRP_REST_Earning_Controller` klasında `user_has_cap` filtrinin düzgün yoxlanılmamasından qaynaqlanır. Plugin dərhal ən son versiyaya yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which plugin is affected by CVE-2026-7534 and what versions are vulnerable?
This vulnerability affects the SUMO Reward Points WordPress plugin in versions 32.7.0 and below.
Is authentication required to exploit CVE-2026-7534?
No, this is an Unauthenticated Stored XSS vulnerability, meaning an attacker can exploit it via the `/wp-json/wc-srp/v1/earning` REST API endpoint without any authentication.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.