Wpexperts

Mycred

7 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.18%
  • Veröffentlicht 26.08.2024 21:15:24
  • Zuletzt bearbeitet 17.10.2025 16:52:50

Missing Authorization vulnerability in myCred.This issue affects myCred: from n/a through 2.7.2.

  • EPSS 0.18%
  • Veröffentlicht 30.11.2023 17:15:10
  • Zuletzt bearbeitet 17.10.2025 16:52:50

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in myCred myCred – Points, Rewards, Gamification, Ranks, Badges & Loyalty Plugin allows Stored XSS.This issue affects myCred – Points, Rewards, Gamific...

  • EPSS 0.05%
  • Veröffentlicht 17.07.2023 14:15:10
  • Zuletzt bearbeitet 17.10.2025 16:52:50

Cross-Site Request Forgery (CSRF) vulnerability in myCred plugin <= 2.5 versions.

Exploit
  • EPSS 0.1%
  • Veröffentlicht 25.04.2022 16:16:08
  • Zuletzt bearbeitet 17.10.2025 16:52:50

The myCred WordPress plugin before 2.4.3.1 does not have authorisation and CSRF checks in its mycred-tools-import-export AJAX action, allowing any authenticated user to call and and retrieve the list of email address present in the blog

Exploit
  • EPSS 0.19%
  • Veröffentlicht 25.04.2022 16:16:07
  • Zuletzt bearbeitet 17.10.2025 16:52:50

The myCred WordPress plugin before 2.4.4.1 does not have any authorisation in place in its mycred-tools-select-user AJAX action, allowing any authenticated user, such as subscriber to call and retrieve all email addresses from the blog

Exploit
  • EPSS 0.07%
  • Veröffentlicht 25.04.2022 16:16:07
  • Zuletzt bearbeitet 17.10.2025 16:52:50

The myCred WordPress plugin before 2.4.3.1 does not have any authorisation and CSRF checks in the mycred-tools-import-export AJAX action, allowing any authenticated users, such as subscribers, to call it and import mycred setup, thus creating badges,...

Exploit
  • EPSS 0.66%
  • Veröffentlicht 29.11.2021 09:15:07
  • Zuletzt bearbeitet 17.10.2025 16:52:50

The myCred WordPress plugin before 2.3 does not validate or escape the fields parameter before using it in a SQL statement, leading to an SQL injection exploitable by any authenticated user