VYPR

Mycred

by Wpexperts

Source repositories

CVEs (7)

  • CVE-2021-24755HigNov 29, 2021
    risk 0.57cvss 8.8epss 0.01

    The myCred WordPress plugin before 2.3 does not validate or escape the fields parameter before using it in a SQL statement, leading to an SQL injection exploitable by any authenticated user

  • CVE-2023-47853MedNov 30, 2023
    risk 0.42cvss 6.5epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in myCred myCred – Points, Rewards, Gamification, Ranks, Badges & Loyalty Plugin allows Stored XSS.This issue affects myCred – Points, Rewards, Gamification, Ranks, Badges &…

  • CVE-2023-35096MedJul 17, 2023
    risk 0.42cvss 6.5epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in myCred plugin <= 2.5 versions.

  • CVE-2024-43214MedAug 26, 2024
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in Saad Iqbal myCred mycred.This issue affects myCred: from n/a through <= 2.7.2.

  • CVE-2022-1092MedApr 25, 2022
    risk 0.28cvss 4.3epss 0.00

    The myCred WordPress plugin before 2.4.3.1 does not have authorisation and CSRF checks in its mycred-tools-import-export AJAX action, allowing any authenticated user to call and and retrieve the list of email address present in the blog

  • CVE-2022-0363MedApr 25, 2022
    risk 0.28cvss 4.3epss 0.00

    The myCred WordPress plugin before 2.4.3.1 does not have any authorisation and CSRF checks in the mycred-tools-import-export AJAX action, allowing any authenticated users, such as subscribers, to call it and import mycred setup, thus creating badges, managing points or creating…

  • CVE-2022-0287MedApr 25, 2022
    risk 0.28cvss 4.3epss 0.01

    The myCred WordPress plugin before 2.4.4.1 does not have any authorisation in place in its mycred-tools-select-user AJAX action, allowing any authenticated user, such as subscriber to call and retrieve all email addresses from the blog