A vulnerability described as critical has been identified in connectordev Loyalty & Promotions Plugin up to 3.1.611.78 on WordPress. This affects the function
bloyal_customer_auto_login of the component AJAX Actions. The manipulation of the argument Customer.ExternalId results in improper privilege management.
This vulnerability is known as CVE-2026-15001. It is possible to launch the attack remotely. No exploit is available.