PT-2026-72142 · WordPress · Bloyal: Loyalty & Promotions By Bloyal

·

CVE-2026-15001

·

Published

2026-08-15

·

Updated

2026-08-20

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions bLoyal: Loyalty & Promotions by bLoyal versions prior to 3.1.611.79
Description This issue allows authenticated users with Subscriber-level access or higher to escalate their privileges to any WordPress user, including the site Administrator. The flaw exists because the AJAX actions save bloyal configuration data and save bloyal accesskeyverification data are registered without capability or nonce checks. An attacker can use these actions to overwrite the bloyal custom loyaltyengine api url and the is bloyal custom api url flag. Subsequently, by triggering the unauthenticated /cart REST route, the bloyal customer auto login() function fetches customer data from an attacker-controlled endpoint and uses the Customer.ExternalId value to call wp set auth cookie(), granting the attacker unauthorized authentication.
Recommendations Update the plugin to a version newer than 3.1.611.78. As a temporary mitigation, restrict access to the save bloyal configuration data and save bloyal accesskeyverification data AJAX actions.

Fix

LPE

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-15001

Affected Products

Bloyal: Loyalty & Promotions By Bloyal