CVE-2026-40786 is a missing authorization vulnerability affecting Long Watch Studio's MyRewards plugin for WooCommerce, impacting versions 5.7.3 and earlier. The flaw stems from incorrectly configured access control security levels that could allow unauthorized users to bypass intended restrictions. The vulnerability carries a CVSS severity score of 4.3 (Medium) with a network-based attack vector requiring low complexity and valid user credentials. Exploitation could result in limited confidentiality impact through unauthorized information disclosure, though integrity and availability are not affected. The attack requires network access and authenticated privileges, which moderates the overall risk profile. There is no evidence of active exploitation in the wild, with the vulnerability not appearing on the CISA Known Exploited Vulnerabilities catalog. The EPSS score of 0.00028 indicates very low probability of exploitation, and the vulnerability remains on the inactive Hot List. Community attention appears minimal, suggesting this represents a lower-priority patching requirement for affected organizations.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Long Watch Studio | MyRewards | >= 0, <= 5.7.3CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.