Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
7.2
CVE-2026-7534
- EPSS 0.32%
- Veröffentlicht 23.07.2026 05:35:53
- Zuletzt bearbeitet 23.07.2026 15:14:51
The SUMO Reward Points plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting via the REST API endpoint `/wp-json/wc-srp/v1/earning` in versions up to, and including, 32.7.0. This is due to the `user_has_cap` filter in the ...
9.8
CVE-2025-32925
- EPSS 0.47%
- Veröffentlicht 19.05.2025 19:56:57
- Zuletzt bearbeitet 23.04.2026 15:29:22
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in FantasticPlugins SUMO Reward Points rewardsystem allows PHP Local File Inclusion.This issue affects SUMO Reward Points: from n/a ...
1