CVE-2026-7534 | FantasticPlugins SUMO Reward Points Plugin up to 32.7.0 on WordPress REST API Endpoint/Admin Pages earning Reason cross site scripting
A vulnerability was found in FantasticPlugins SUMO Reward Points Plugin up to 32.7.0 on WordPress. It has been classified as problematic. Affected by this issue is the function SRP_REST_Earning_Controller.create_items/SRP_Master_Log.column_default of the file /wp-json/wc-srp/v1/earning of the component REST API Endpoint/Admin Pages. This manipulation of the argument Reason causes cross site scripting.
This vulnerability is handled as CVE-2026-7534. The attack can be initiated remotely. There is not any exploit available.VulDB Recent EntriesRead More