WordPress Spin Wheel Plugin Prize Manipulation Vulnerability

Vulnerability

A vulnerability exists in the Spin Wheel plugin for WordPress, allowing for client-side manipulation of prize selections. This issue is present in all versions through 2.1.0. The vulnerability arises because the plugin does not validate or randomize prize selection data from users, enabling unauthenticated attackers to alter the 'prize_index' parameter and consistently choose the most valuable prizes.

Impact

Exploitation of this vulnerability allows for unauthorized manipulation of prize selections, potentially leading to unfair advantages in contests or giveaways.

Reproduction

To reproduce this vulnerability, an unauthenticated user can send a request to the server with a modified 'prize_index' parameter. This can be done using browser developer tools or a tool like Postman. The server will process the request and award the prize corresponding to the selected index, without any validation or randomization.

Remediation

Users are advised to update the Spin Wheel plugin to version 2.1.1 or later.

Added: Jan 17, 2026, 7:19 AM
Updated: Jan 17, 2026, 7:19 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
8.0
remediation
0.0
relevance
2.1
threat
4.8
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.