VYPR
High severity8.8NVD Advisory· Published Aug 15, 2026

CVE-2026-15001

CVE-2026-15001

Description

The bLoyal: Loyalty & Promotions by bLoyal plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.1.611.78. This is due to the AJAX actions save_bloyal_configuration_data and save_bloyal_accesskeyverification_data being registered without any capability or nonce checks, and the bloyal_customer_auto_login function unconditionally trusting the Customer.ExternalId value returned by whichever API URL is stored in the plugin's options. This makes it possible for authenticated attackers, with Subscriber-level access and above, to overwrite the plugin's bLoyal Loyalty Engine API URL (bloyal_custom_loyaltyengine_api_url) and the is_bloyal_custom_api_url flag via the unprotected AJAX actions, then trigger the unauthenticated /cart REST route to cause bloyal_customer_auto_login to fetch customer data from an attacker-controlled endpoint and call wp_set_auth_cookie() with an attacker-supplied Customer.ExternalId, thereby authenticating as any WordPress user including the site Administrator.

Affected products

1

Patches

Vulnerability mechanics

References

10

News mentions

0

No linked articles in our index yet.