Medium severity6.1NVD Advisory· Published Jan 24, 2022· Updated Jun 17, 2026
CVE-2021-25015
CVE-2021-25015
Description
The myCred WordPress plugin before 2.4 does not sanitise and escape the search query before outputting it back in the history dashboard page, leading to a Reflected Cross-Site Scripting issue
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2(expand)+ 1 more
- (no CPE)
- (no CPE)range: <2.4
Package: https://wordpress.org/plugins/mycred
Patches
Vulnerability mechanics
References
2- plugins.trac.wordpress.org/changeset/2648350/mycrednvdPatchThird Party Advisory
- wpscan.com/vulnerability/7608829d-2820-49e2-a10e-e93eb3005f68nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.