{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/bloyal/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-15001"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Loyalty \u0026 Promotions by bLoyal (3.1.611.78)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["bLoyal"],"content_html":"\u003cp\u003eThe bLoyal: Loyalty \u0026amp; Promotions plugin for WordPress (versions 3.1.611.78 and earlier) is susceptible to a critical privilege escalation vulnerability, tracked as CVE-2026-15001. The flaw stems from the insecure implementation of AJAX actions \u003ccode\u003esave_bloyal_configuration_data\u003c/code\u003e and \u003ccode\u003esave_bloyal_accesskeyverification_data\u003c/code\u003e, which lack necessary capability and nonce validation. Furthermore, the \u003ccode\u003ebloyal_customer_auto_login\u003c/code\u003e function blindly trusts the \u003ccode\u003eCustomer.ExternalId\u003c/code\u003e returned by an API endpoint configurable within the plugin. An attacker with minimal Subscriber-level access can modify these plugin settings to point to an attacker-controlled API. By subsequently triggering the \u003ccode\u003e/cart\u003c/code\u003e REST route, the attacker forces the plugin to fetch a malicious user payload from their own server, leading to an unauthorized call to \u003ccode\u003ewp_set_auth_cookie()\u003c/code\u003e that elevates the attacker's session to that of any site user, including administrators.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in full site compromise by granting the attacker administrator-level access. As this vulnerability affects a plugin with e-commerce and loyalty functionality, targets include any WordPress site utilizing the affected versions for customer management and promotions.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the bLoyal: Loyalty \u0026amp; Promotions plugin to the latest version immediately to remediate CVE-2026-15001.\u003c/li\u003e\n\u003cli\u003eAudit WordPress site logs for unauthorized requests to the \u003ccode\u003e/wp-admin/admin-ajax.php\u003c/code\u003e endpoint containing \u003ccode\u003esave_bloyal_configuration_data\u003c/code\u003e or \u003ccode\u003esave_bloyal_accesskeyverification_data\u003c/code\u003e parameters originating from low-privileged user accounts.\u003c/li\u003e\n\u003cli\u003eMonitor site configuration changes for unexpected modifications to the \u003ccode\u003ebloyal_custom_loyaltyengine_api_url\u003c/code\u003e option in the WordPress database.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-15T04:16:39Z","date_published":"2026-08-15T04:16:39Z","id":"https://feed.craftedsignal.io/briefs/2026-08-bloyal-privesc/","summary":"The bLoyal: Loyalty \u0026 Promotions plugin for WordPress contains an unauthenticated configuration modification and privilege escalation vulnerability, CVE-2026-15001, allowing low-privileged users to assume administrator accounts.","title":"Privilege Escalation in bLoyal: Loyalty \u0026 Promotions WordPress Plugin","url":"https://feed.craftedsignal.io/briefs/2026-08-bloyal-privesc/"}],"language":"en","title":"CraftedSignal Threat Feed - BLoyal","version":"https://jsonfeed.org/version/1.1"}