{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/sumo-reward-points-plugin--32.7.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.2,"id":"CVE-2026-7534"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["SUMO Reward Points plugin \u003c 32.7.0","WordPress"],"_cs_severities":["high"],"_cs_tags":["wordpress","xss","web-vulnerability","plugin","stored-xss"],"_cs_type":"advisory","_cs_vendors":["SUMO","WordPress"],"content_html":"\u003cp\u003eA critical vulnerability, identified as CVE-2026-7534, has been discovered in the SUMO Reward Points plugin for WordPress, affecting all versions up to and including 32.7.0. This flaw allows unauthenticated attackers to perform Stored Cross-Site Scripting (XSS) by injecting arbitrary web scripts into the reward points log. The vulnerability stems from an improper capability grant (\u003ccode\u003ers_earning_read\u003c/code\u003e) to all users, including unauthenticated visitors, combined with a lack of sanitization for the \u003ccode\u003ereason\u003c/code\u003e parameter in the \u003ccode\u003ecreate_items()\u003c/code\u003e function and missing output escaping in the \u003ccode\u003ecolumn_default()\u003c/code\u003e method of \u003ccode\u003eSRP_Master_Log\u003c/code\u003e. Attackers can exploit this by sending a crafted request to the \u003ccode\u003e/wp-json/wc-srp/v1/earning\u003c/code\u003e REST API endpoint. The injected scripts subsequently execute whenever an administrator views the Master Log or User Reward Points admin pages, leading to potential administrative compromise, session hijacking, or further payload delivery.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn unauthenticated attacker crafts a malicious HTTP POST request containing JavaScript payload within the \u003ccode\u003ereason\u003c/code\u003e parameter.\u003c/li\u003e\n\u003cli\u003eThe attacker sends this request to the vulnerable REST API endpoint \u003ccode\u003e/wp-json/wc-srp/v1/earning\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eDue to the \u003ccode\u003euser_has_cap\u003c/code\u003e filter unconditionally granting \u003ccode\u003ers_earning_read\u003c/code\u003e capability to all users, the request is processed even without authentication.\u003c/li\u003e\n\u003cli\u003eThe \u003ccode\u003ecreate_items()\u003c/code\u003e function processes the request without properly sanitizing the \u003ccode\u003ereason\u003c/code\u003e parameter, storing the malicious script in the reward points log.\u003c/li\u003e\n\u003cli\u003eAn administrator later accesses the WordPress admin dashboard and navigates to the Master Log or User Reward Points admin pages.\u003c/li\u003e\n\u003cli\u003eThe \u003ccode\u003ecolumn_default()\u003c/code\u003e method of \u003ccode\u003eSRP_Master_Log\u003c/code\u003e retrieves the stored log entry without proper output escaping.\u003c/li\u003e\n\u003cli\u003eThe malicious JavaScript injected by the attacker executes within the administrator's browser context.\u003c/li\u003e\n\u003cli\u003eThe attacker gains control over the administrator's session, performs actions on their behalf, or redirects them to a malicious site.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-7534 leads to unauthenticated Stored Cross-Site Scripting, allowing attackers to execute arbitrary malicious scripts within the browser of any administrator viewing the affected log pages. This can result in session hijacking, complete administrative control over the WordPress site, redirection to phishing sites, or further client-side attacks. The wide adoption of WordPress and this plugin means that a significant number of websites are potentially at risk, and exploitation could lead to substantial data breaches, website defacement, or malware distribution to site visitors. The CVSS v3.1 Base Score of 7.2 indicates a high severity risk.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDeploy the provided Sigma rule to your SIEM to detect attempts at exploiting CVE-2026-7534 against the \u003ccode\u003e/wp-json/wc-srp/v1/earning\u003c/code\u003e endpoint.\u003c/li\u003e\n\u003cli\u003eMonitor web server access logs for HTTP POST requests containing script-like content in the query parameters targeting \u003ccode\u003e/wp-json/wc-srp/v1/earning\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003ePatch CVE-2026-7534 by updating the SUMO Reward Points plugin for WordPress to a version greater than 32.7.0 immediately.\u003c/li\u003e\n\u003cli\u003eImplement a Web Application Firewall (WAF) with rules to detect and block XSS payloads in request parameters, specifically for the \u003ccode\u003e/wp-json/wc-srp/v1/earning\u003c/code\u003e REST API endpoint.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-23T06:18:55Z","date_published":"2026-07-23T06:18:55Z","id":"https://feed.craftedsignal.io/briefs/2026-07-sumo-reward-points-xss/","summary":"The SUMO Reward Points plugin for WordPress, versions up to and including 32.7.0, is vulnerable to CVE-2026-7534, an Unauthenticated Stored Cross-Site Scripting flaw that allows attackers to inject arbitrary web scripts into the reward points log via the `/wp-json/wc-srp/v1/earning` REST API endpoint, executing when an administrator accesses specific admin pages.","title":"SUMO Reward Points WordPress Plugin Vulnerable to Unauthenticated Stored XSS via REST API (CVE-2026-7534)","url":"https://feed.craftedsignal.io/briefs/2026-07-sumo-reward-points-xss/"}],"language":"en","title":"CraftedSignal Threat Feed - SUMO Reward Points Plugin \u003c 32.7.0","version":"https://jsonfeed.org/version/1.1"}