---
id: CVE-2026-93510
title: >-
  The Points and Rewards for WooCommerce WordPress plugin before 2.10.4 does not
  validate the claimed reward amount or restrict who can call its Win Wheel
  claim handler, allowing authenticated users, Subscriber and above, to credit
  their o…
summary: >-
  The Points and Rewards for WooCommerce WordPress plugin before 2.10.4 does not
  validate the claimed reward amount or restrict who can call its Win Wheel
  claim handler, allowing authenticated users, Subscriber and above, to credit
  their o…
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'
cwe:
  - CWE-862
product: Points and Rewards for WooCommerce
affected:
  - points_and_rewards_for_woocommerce < 2.10.4
published: '2026-09-23'
updated: '2026-09-23'
sourceUpdated: '2026-09-23T18:12:32.050'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-93510'
references:
  - url: 'https://wpscan.com/vulnerability/b721d8bb-2426-4635-a419-07074168bd82/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
epss: 0.00152
epssPercentile: 0.03625
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-23T10:36:17.110125Z'
ingestedAt: '2026-09-23T06:17:57.901Z'
---

## Overview

The Points and Rewards for WooCommerce WordPress plugin before 2.10.4 does not validate the claimed reward amount or restrict who can call its Win Wheel claim handler, allowing authenticated users, Subscriber and above, to credit their own account with an arbitrary and unlimited amount of loyalty points and, where a companion wallet Points and Rewards for WooCommerce WordPress plugin before 2.10.4 is active, wallet balance.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
