CVE-2026-11782

Points and Rewards for WooCommerce < 2.10.1 - Unauthenticated Arbitrary User Wallet & Points Manipulation via IDOR

The Points and Rewards for WooCommerce WordPress plugin before 2.10.1 does not have authorisation checks in place on a wallet and points update action that is available to unauthenticated users, and does not verify that the requester owns the account being changed, allowing unauthenticated attackers to arbitrarily modify or corrupt (including driving it negative) the stored wallet balance and loyalty points of any user. Modifying the wallet balance additionally requires the companion Wallet System for WooCommerce Points and Rewards for WooCommerce WordPress plugin before 2.10.1 to be active.


We have discovered 694 live websites that are affected by CVE-2026-11782.

Run a Free Instant Scan




Affected Software

Product  Points And Rewards For Woocommerce
Category Wordpress Plugins
Vulnerable Domains694 live websites (100% of Points And Rewards For Woocommerce install base)
Vulnerable Versions
  • from 0 through 2.10.1
Vulnerable Versions Count43 versions ( 100% of all versions)


Common Weakness Enumeration

CWE-284 Improper Access Control



Details

  • Published - Jul 30, 2026
  • Updated - Jul 30, 2026

Credits

  • Sanjorn Keeratirungsan (finder)
  • WPScan (coordinator)

Website Distribution by Country

Number of websites using CVE-2026-11782
United States209 websites



France49 websites
Japan32 websites
GB29 websites
Germany26 websites
Cyprus20 websites
Malaysia17 websites
India17 websites
Italy17 websites
Singapore15 websites

Website Distribution by TLD

Number of websites using CVE-2026-11782
.com334 websites
.fr25 websites
.nl21 websites
.co.uk18 websites
.net16 websites
.com.au16 websites
.it15 websites
.pl12 websites
.com.br11 websites
.jp10 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-11782

Top websites that are affected by CVE-2026-11782. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*******.jp Japan***,***
*******.com United States***,***
*************.net United States***,***
************.com United States***,***
*********.org United States***,***
***********.com United States***,***
**************.com United States*,***,***
*********.***.ua Ukraine*,***,***
*********************.com United States*,***,***
*******.hu Hungary*,***,***
See full domain list

FAQ

CVE-2026-11782 is Improper Access Control in Points And Rewards For Woocommerce
A total of 694 websites have been identified as vulnerable to CVE-2026-11782, based on global website indexing conducted by WebTechSurvey.
The Points And Rewards For Woocommerce is affected by the CVE-2026-11782 vulnerability.
Points And Rewards For Woocommerce versions up to 2.10.1 are vulnerable to CVE-2026-11782.
CVE-2026-11782 is resolved in version 2.10.1 of Points And Rewards For Woocommerce.