Description
The Spin Wheel plugin for WordPress is vulnerable to client-side prize manipulation in all versions up to, and including, 2.1.0. This is due to the plugin trusting client-supplied prize selection data without server-side validation or randomization. This makes it possible for unauthenticated attackers to manipulate which prize they win by modifying the 'prize_index' parameter sent to the server, allowing them to always select the most valuable prizes.
Problem types
CWE-602 Client-Side Enforcement of Server-Side Security
Product status
* (semver)
Timeline
| 2026-01-09: | Vendor Notified |
| 2026-01-16: | Disclosed |
Credits
jason carle
References
www.wordfence.com/...-f633-41a6-b2d7-bcb3f1d026b7?source=cve
plugins.trac.wordpress.org/...nk/includes/class-swp-ajax.php
plugins.trac.wordpress.org/....2/includes/class-swp-ajax.php
plugins.trac.wordpress.org/...in-wheel&sfp_email=&sfph_mail=