HIGH
FantasticPlugins
CVE published 2026-07-23
CVE-2026-7534
CVE-2026-7534 is an Unauthenticated Stored Cross-Site Scripting vulnerability in the SUMO Reward Points plugin for WordPress. The vulnerability exists in versions up to and including 32.7.0 and is caused by the unconditional granting of the custom 'rs_earning_read' capability to all users, including unauthenticated visitors, via the 'user_has_cap' filter in the 'SRP_REST_Earning_Controller' class. Additio [truncated]