WordPress security by component
MyRewards
Plugin description
MyRewards is a WordPress component with 3 published CVE records in this archive. The latest tracked vulnerability was published Apr 15, 2026; the highest CVE/CNA score is 6.5.
Plugin slug:
woorewardsLatest vulnerability
CVE-2026-40786: MyRewards: A security weakness
MyRewards is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 5.7.3.
| Safe version |
|
||
|---|---|---|---|
| Apr 15, 2026 |
CVE-2026-40786
MyRewards: A security weakness
MyRewards is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 5.7.3.
|
5.7.4 |
CVE4.3
NVDPending
|
| Feb 04, 2026 |
CVE-2025-15260
MyRewards – Loyalty Points and Rewards for WooCommerce: A security weakness
MyRewards – Loyalty Points and Rewards for WooCommerce is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE6.5
NVDPending
|
| Apr 22, 2024 |
CVE-2024-32688
MyRewards: A security weakness
MyRewards is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE6.5
NVDPending
|