WordPress security by component
myCred
Plugin description
myCred is a WordPress component with 28 published CVE records in this archive. The latest tracked vulnerability was published Jul 13, 2026; the highest CVE/CNA score is 9.8.
Plugin slug:
mycredLatest vulnerability
CVE-2026-61968: myCred: A security weakness
myCred is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 3.1.2.
| Safe version |
|
||
|---|---|---|---|
| Jul 13, 2026 |
CVE-2026-61968
myCred: A security weakness
myCred is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 3.1.2.
|
3.2.0 |
CVE5.4
NVDPending
|
| Jun 17, 2026 |
CVE-2026-8607
Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred: Cross-site scripting
Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 3.1.
|
> 3.1 |
CVE6.4
NVDPending
|
| Jun 15, 2026 |
CVE-2026-40794
myCred: A security weakness
myCred is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 3.0.3.
|
3.0.4 |
CVE6.5
NVDPending
|
| Jun 01, 2026 |
CVE-2026-42676
myCred: Cross-site scripting
myCred is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 3.0.4.
|
3.0.5 |
CVE6.5
NVDPending
|
| Feb 19, 2026 |
CVE-2026-27440
myCred: Cross-site scripting
myCred is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVDPending
|
| Feb 14, 2026 |
CVE-2026-0550
myCred: Cross-site scripting
myCred is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVDPending
|
| Feb 03, 2026 |
CVE-2026-24951
myCred: A security weakness
myCred is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Dec 19, 2025 |
CVE-2025-12361
myCred – Points Management System For Gamification, Ranks, Badges, and Loyalty Program: A security weakness
myCred – Points Management System For Gamification, Ranks, Badges, and Loyalty Program is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Dec 13, 2025 |
CVE-2025-12362
myCred – Points Management System For Gamification, Ranks, Badges, and Loyalty Program: A security weakness
myCred – Points Management System For Gamification, Ranks, Badges, and Loyalty Program is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Aug 14, 2025 |
CVE-2025-54668
myCred: Cross-site scripting
myCred is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVDPending
|
| Aug 14, 2025 |
CVE-2025-54667
myCred: A security weakness
myCred is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Jun 17, 2025 |
CVE-2025-49872
myCred: A security weakness
myCred is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Jun 17, 2025 |
CVE-2025-49857
myCred: A security weakness
myCred is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Dec 06, 2024 |
CVE-2024-11201
myCred – Loyalty Points and Rewards: Cross-site scripting
myCred – Loyalty Points and Rewards is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVDPending
|
| Nov 08, 2024 |
CVE-2024-10187
myCred – Loyalty Points and Rewards: Cross-site scripting
myCred – Loyalty Points and Rewards is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Sep 25, 2024 |
CVE-2024-8658
myCred – Loyalty Points and Rewards: A security weakness
myCred – Loyalty Points and Rewards is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Aug 26, 2024 |
CVE-2024-43214
myCred: A security weakness
myCred is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVD5.3
|
| Aug 19, 2024 |
CVE-2024-43354
myCred: Code execution
myCred is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
|
See mitigation notes |
CVE9.8
NVDPending
|
| Aug 18, 2024 |
CVE-2024-43353
myCred: Cross-site scripting
myCred is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVDPending
|
| Apr 24, 2024 |
CVE-2024-32711
myCred: Cross-site scripting
myCred is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVDPending
|
| Nov 30, 2023 |
CVE-2023-47853
myCred – Points, Rewards, Gamification, Ranks, Badges & Loyalty Plugin: Cross-site scripting
myCred – Points, Rewards, Gamification, Ranks, Badges & Loyalty Plugin is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVD5.4
|
| Jul 17, 2023 |
CVE-2023-35096
Mycred: Cross-site request forgery
Mycred is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE6.5
NVD8.8
|
| Apr 25, 2022 |
CVE-2022-1092
myCred: Cross-site request forgery
myCred is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE4.3
NVD4.3
|
| Apr 25, 2022 |
CVE-2022-0363
myCred: Cross-site request forgery
myCred is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE4.3
NVD4.3
|
| Apr 25, 2022 |
CVE-2022-0287
myCred: A security weakness
myCred is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVD4.3
|
| Jan 24, 2022 |
CVE-2021-25015
myCred: Cross-site scripting
myCred is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.1
NVD6.1
|
| Nov 29, 2021 |
CVE-2021-24755
myCred: SQL injection
myCred is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE8.8
NVD8.8
|
| Nov 29, 2021 |
CVE-2017-20008
myCred: Cross-site scripting
myCred is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.1
NVD6.1
|