The bLoyal: Loyalty & Promotions by bLoyal plugin for WordPress is vulnerable to Privilege...
🔗 CVE IDs covered (1)
📋 Description
The bLoyal: Loyalty & Promotions by bLoyal plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.1.611.78. This is due to the AJAX actions save_bloyal_configuration_data and save_bloyal_accesskeyverification_data being registered without any capability or nonce checks, and the bloyal_customer_auto_login function unconditionally trusting the Customer.ExternalId value returned by whichever API URL is stored in the plugin's options. This makes it possible for authenticated attackers, with Subscriber-level access and above, to overwrite the plugin's bLoyal Loyalty Engine API URL (bloyal_custom_loyaltyengine_api_url) and the is_bloyal_custom_api_url flag via the unprotected AJAX actions, then trigger the unauthenticated /cart REST route to cause bloyal_customer_auto_login to fetch customer data from an attacker-controlled endpoint and call wp_set_auth_cookie() with an attacker-supplied Customer.ExternalId, thereby authenticating as any WordPress user including the site Administrator.
🔗 References (12)
- https://nvd.nist.gov/vuln/detail/CVE-2026-15001
- https://plugins.trac.wordpress.org/browser/bloyal/tags/3.1.611.78/app/controller/class-bloyalcontroller.php#L2429
- https://plugins.trac.wordpress.org/browser/bloyal/tags/3.1.611.78/app/controller/class-bloyalcontroller.php#L2470
- https://plugins.trac.wordpress.org/browser/bloyal/tags/3.1.611.78/app/controller/class-bloyalcontroller.php#L2512
- https://plugins.trac.wordpress.org/browser/bloyal/tags/3.1.611.78/app/controller/class-bloyalcontroller.php#L421
- https://plugins.trac.wordpress.org/browser/bloyal/tags/3.1.611.78/app/controller/class-bloyalcontroller.php#L494
- https://plugins.trac.wordpress.org/browser/bloyal/tags/3.1.611.78/app/controller/class-bloyalcontroller.php#L806
- https://plugins.trac.wordpress.org/browser/bloyal/tags/3.1.611.78/bloyal.php#L1196
- https://plugins.trac.wordpress.org/browser/bloyal/tags/3.1.611.78/bloyal.php#L1553
- https://plugins.trac.wordpress.org/browser/bloyal/tags/3.1.611.78/bloyal.php#L1596
- https://www.wordfence.com/threat-intel/vulnerabilities/id/ba4b58ad-97b3-482a-bf24-1fa85d6ef93d?source=cve
- https://github.com/advisories/GHSA-5h38-4j4g-wf4g