PatchSiren cyber security CVE debrief
CVE-2026-7534 FantasticPlugins CVE debrief
CVE-2026-7534 is an Unauthenticated Stored Cross-Site Scripting vulnerability in the SUMO Reward Points plugin for WordPress. The vulnerability exists in versions up to and including 32.7.0 and is caused by the unconditional granting of the custom 'rs_earning_read' capability to all users, including unauthenticated visitors, via the 'user_has_cap' filter in the 'SRP_REST_Earning_Controller' class. Additionally, the 'reason' parameter in the 'create_items()' function lacks sanitization, and the 'column_default()' method of 'SRP_Master_Log' lacks output escaping.
- Vendor
- FantasticPlugins
- Product
- SUMO Reward Points for WooCommerce
- CVSS
- HIGH 7.2
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-23
- Original CVE updated
- 2026-07-23
- Advisory published
- 2026-07-23
- Advisory updated
- 2026-07-23
Who should care
Administrators of WordPress installations using the SUMO Reward Points plugin, especially those with versions up to and including 32.7.0, should be aware of this vulnerability and take immediate action to protect their sites.
Technical summary
The SUMO Reward Points plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting via the REST API endpoint '/wp-json/wc-srp/v1/earning' in versions up to, and including, 32.7.0. This is due to the 'user_has_cap' filter in the 'SRP_REST_Earning_Controller' class unconditionally granting the custom 'rs_earning_read' capability to all users — including unauthenticated visitors — combined with missing sanitization of the 'reason' parameter in the 'create_items()' function and missing output escaping in the 'column_default()' method of 'SRP_Master_Log'.
Defensive priority
High
Recommended defensive actions
- Update the SUMO Reward Points plugin to a version beyond 32.7.0.
- Implement additional security measures such as Web Application Firewall (WAF) rules to detect and prevent cross-site scripting attacks.
- Regularly monitor the WordPress installation for any suspicious activity.
- Restrict access to the REST API endpoint '/wp-json/wc-srp/v1/earning' to authenticated users only.
- Consider using a security plugin to provide additional protection against cross-site scripting attacks.
Evidence notes
The CVE record was published on 2026-07-23T06:16:50.780Z and has not been modified since then. The NVD entry is currently in the 'Received' status. Evidence is limited to public CVE and NVD information. Defenders should verify managed environments for affected deployments, review official advisories, and plan updates or mitigations. Compensating controls and monitoring may be necessary for exposed systems.
Official resources
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-23T06:16:50.780Z and has not been modified since then. The NVD entry is currently in the 'Received' status.