CVE-2026-10628

Points and Rewards for WooCommerce <= 2.10.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Modification via Multiple AJAX Actions

The Points and Rewards for WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.10.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to convert and drain any user's reward points into wallet balance, exfiltrate all users' emails and point balances to an attacker-controlled Klaviyo account, overwrite the site's Klaviyo public API key, block or unblock arbitrary users from the points system, and modify campaign banner and heading settings. The nonce used for authentication of these requests (wps-wpr-verify-nonce) is injected into every public-facing page via wp_localize_script(), and the wps_wpr_generate_custom_wallet handler is additionally registered on the wp_ajax_nopriv_ hook, meaning unauthenticated visitors can also obtain a valid nonce and exploit that specific action.


We have discovered 694 live websites that are affected by CVE-2026-10628.

Run a Free Instant Scan




Affected Software

Product  Points And Rewards For Woocommerce
Category Wordpress Plugins
Vulnerable Domains694 live websites (100% of Points And Rewards For Woocommerce install base)
Vulnerable Versions
  • from 0 through 2.10.1
Vulnerable Versions Count43 versions ( 100% of all versions)


Common Weakness Enumeration

CWE-862 Missing Authorization



Details

  • Published - Jul 11, 2026
  • Updated - Jul 15, 2026

Credits

  • Latz (finder)

Website Distribution by Country

Number of websites using CVE-2026-10628
United States209 websites



France49 websites
Japan32 websites
GB29 websites
Germany26 websites
Cyprus20 websites
Malaysia17 websites
India17 websites
Italy17 websites
Singapore15 websites

Website Distribution by TLD

Number of websites using CVE-2026-10628
.com334 websites
.fr25 websites
.nl21 websites
.co.uk18 websites
.net16 websites
.com.au16 websites
.it15 websites
.pl12 websites
.com.br11 websites
.jp10 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-10628

Top websites that are affected by CVE-2026-10628. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*******.jp Japan***,***
*******.com United States***,***
*************.net United States***,***
************.com United States***,***
*********.org United States***,***
***********.com United States***,***
**************.com United States*,***,***
*********.***.ua Ukraine*,***,***
*********************.com United States*,***,***
*******.hu Hungary*,***,***
See full domain list

FAQ

CVE-2026-10628 is Missing Authorization in Points And Rewards For Woocommerce
A total of 694 websites have been identified as vulnerable to CVE-2026-10628, based on global website indexing conducted by WebTechSurvey.
The Points And Rewards For Woocommerce is affected by the CVE-2026-10628 vulnerability.
Points And Rewards For Woocommerce versions up to and including 2.10.1 are vulnerable to CVE-2026-10628.

References