VYPR

SUMO Reward Points

by WordPress

CVEs (2)

  • CVE-2025-32925HigMay 19, 2025
    risk 0.54cvss 8.3epss 0.00

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in FantasticPlugins SUMO Reward Points rewardsystem allows PHP Local File Inclusion.This issue affects SUMO Reward Points: from n/a through <= 30.7.0.

  • CVE-2026-7534HigJul 23, 2026
    risk 0.00cvss 7.2epss 0.00

    The SUMO Reward Points plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting via the REST API endpoint `/wp-json/wc-srp/v1/earning` in versions up to, and including, 32.7.0. This is due to the `user_has_cap` filter in the `SRP_REST_Earning_Controller`…