VYPR

MyRewards

by WordPress

CVEs (3)

  • CVE-2025-15260MedFeb 4, 2026
    risk 0.42cvss 6.5epss 0.00

    The MyRewards – Loyalty Points and Rewards for WooCommerce plugin for WordPress is vulnerable to missing authorization in all versions up to, and including, 5.6.1. This is due to the plugin not properly verifying that a user is authorized to perform an action in the 'ajax'…

  • CVE-2024-32688MedApr 22, 2024
    risk 0.42cvss 6.5epss 0.00

    Missing Authorization vulnerability in Long Watch Studio MyRewards.This issue affects MyRewards: from n/a through 5.3.0.

  • CVE-2026-40786MedApr 15, 2026
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in Long Watch Studio MyRewards woorewards allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MyRewards: from n/a through <= 5.7.3.