CVE-2026-32520
WordPress RewardsWP plugin <= 1.0.4 - Privilege Escalation vulnerability
CVSS Score
9.8
EPSS Score
0.0%
EPSS Percentile
4th
Incorrect Privilege Assignment vulnerability in Andrew Munro / AffiliateWP RewardsWP rewardswp allows Privilege Escalation.This issue affects RewardsWP: from n/a through <= 1.0.4.
| CWE | CWE-266 |
| Vendor | andrew munro / affiliatewp |
| Product | rewardswp |
| Published | Mar 25, 2026 |
| Last Updated | Mar 26, 2026 |
Stay Ahead of the Next One
Get instant alerts for andrew munro / affiliatewp rewardswp
Be the first to know when new critical vulnerabilities affecting andrew munro / affiliatewp rewardswp are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Andrew Munro / AffiliateWP / RewardsWP
n/a โค <= 1.0.4
References
Credits
daroo | Patchstack Bug Bounty Program