PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-7534 FantasticPlugins CVE debrief

CVE-2026-7534 is an Unauthenticated Stored Cross-Site Scripting vulnerability in the SUMO Reward Points plugin for WordPress. The vulnerability exists in versions up to and including 32.7.0 and is caused by the unconditional granting of the custom 'rs_earning_read' capability to all users, including unauthenticated visitors, via the 'user_has_cap' filter in the 'SRP_REST_Earning_Controller' class. Additionally, the 'reason' parameter in the 'create_items()' function lacks sanitization, and the 'column_default()' method of 'SRP_Master_Log' lacks output escaping.

Vendor
FantasticPlugins
Product
SUMO Reward Points for WooCommerce
CVSS
HIGH 7.2
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-23
Original CVE updated
2026-07-23
Advisory published
2026-07-23
Advisory updated
2026-07-23

Who should care

Administrators of WordPress installations using the SUMO Reward Points plugin, especially those with versions up to and including 32.7.0, should be aware of this vulnerability and take immediate action to protect their sites.

Technical summary

The SUMO Reward Points plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting via the REST API endpoint '/wp-json/wc-srp/v1/earning' in versions up to, and including, 32.7.0. This is due to the 'user_has_cap' filter in the 'SRP_REST_Earning_Controller' class unconditionally granting the custom 'rs_earning_read' capability to all users — including unauthenticated visitors — combined with missing sanitization of the 'reason' parameter in the 'create_items()' function and missing output escaping in the 'column_default()' method of 'SRP_Master_Log'.

Defensive priority

High

Recommended defensive actions

  • Update the SUMO Reward Points plugin to a version beyond 32.7.0.
  • Implement additional security measures such as Web Application Firewall (WAF) rules to detect and prevent cross-site scripting attacks.
  • Regularly monitor the WordPress installation for any suspicious activity.
  • Restrict access to the REST API endpoint '/wp-json/wc-srp/v1/earning' to authenticated users only.
  • Consider using a security plugin to provide additional protection against cross-site scripting attacks.

Evidence notes

The CVE record was published on 2026-07-23T06:16:50.780Z and has not been modified since then. The NVD entry is currently in the 'Received' status. Evidence is limited to public CVE and NVD information. Defenders should verify managed environments for affected deployments, review official advisories, and plan updates or mitigations. Compensating controls and monitoring may be necessary for exposed systems.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-23T06:16:50.780Z and has not been modified since then. The NVD entry is currently in the 'Received' status.