PT-2026-72142 · WordPress · Bloyal: Loyalty & Promotions By Bloyal
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
bLoyal: Loyalty & Promotions by bLoyal versions prior to 3.1.611.79
Description
This issue allows authenticated users with Subscriber-level access or higher to escalate their privileges to any WordPress user, including the site Administrator. The flaw exists because the AJAX actions
save bloyal configuration data and save bloyal accesskeyverification data are registered without capability or nonce checks. An attacker can use these actions to overwrite the bloyal custom loyaltyengine api url and the is bloyal custom api url flag. Subsequently, by triggering the unauthenticated /cart REST route, the bloyal customer auto login() function fetches customer data from an attacker-controlled endpoint and uses the Customer.ExternalId value to call wp set auth cookie(), granting the attacker unauthorized authentication.Recommendations
Update the plugin to a version newer than 3.1.611.78.
As a temporary mitigation, restrict access to the
save bloyal configuration data and save bloyal accesskeyverification data AJAX actions.Fix
LPE
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Bloyal: Loyalty & Promotions By Bloyal