Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

myCred — Vulnerabilities & Security Advisories 18

All 18 CVE vulnerabilities found in myCred, with AI-generated Chinese analysis, references, and POCs.

This page aggregates vulnerability data for myCred, a popular points and reward system plugin for WordPress, focusing on specific weakness types and security tags. It collects a variety of reported security flaws, including cross-site scripting, insecure direct object references, and permission misconfigurations, covering incidents disclosed from 2016 to the present. Readers can utilize this resource to track the vendor's advisory patterns over time, understand the specific characteristics of common weakness classes affecting this ecosystem, or review the complete vulnerability history associated with the product to assess its long-term security posture. By centralizing these entries, the page provides a factual overview of how security issues have been identified and addressed within the myCred codebase. The data serves as a reference for security professionals and system administrators who need to evaluate the risk profile of this component within their WordPress installations. This aggregation facilitates a broader understanding of the threat landscape without requiring navigation through disparate individual bulletin pages. The focus remains strictly on historical data collection and classification, offering a clear view of the product's security track record and the evolution of its vulnerabilities across various versions.

Vendor: Unknown

CVE ID Title CVSS Severity Published
CVE-2026-15150 myCred < 3.2.5 - Unauthenticated Payment Bypass via Missing PayPal IPN Receiver Verification in buyCRED 5.3 Medium 2026-08-21
CVE-2026-61968 WordPress myCred plugin <= 3.1.2 - Broken Access Control vulnerability CWE-862 5.4 Medium 2026-07-13
CVE-2026-40794 WordPress myCred plugin <= 3.0.3 - Broken Access Control vulnerability CWE-862 6.5 Medium 2026-06-15
CVE-2026-42676 WordPress myCred plugin <= 3.0.4 - Cross Site Scripting (XSS) vulnerability CWE-79 6.5 Medium 2026-06-01
CVE-2026-27440 WordPress myCred plugin <= 2.9.7.6 - Cross Site Scripting (XSS) vulnerability CWE-79 6.5 Medium 2026-02-19
CVE-2026-24951 WordPress myCred plugin <= 2.9.7.3 - Broken Access Control vulnerability CWE-862 4.3 Medium 2026-02-03
CVE-2025-54668 WordPress myCred plugin <= 2.9.4.3 - Cross Site Scripting (XSS) Vulnerability CWE-79 6.5 Medium 2025-08-14
CVE-2025-54667 WordPress myCred plugin <= 2.9.4.3 - Race Condition Vulnerability CWE-367 5.3 Medium 2025-08-14
CVE-2025-49857 WordPress myCred plugin <= 2.9.4.2 - Broken Access Control Vulnerability CWE-862 4.3 Medium 2025-06-17
CVE-2025-49872 WordPress myCred plugin <= 2.9.4.2 - Broken Access Control Vulnerability CWE-862 5.3 Medium 2025-06-17
CVE-2024-43214 WordPress myCred plugin <= 2.7.2 - Sensitive Data Exposure vulnerability CWE-862 5.3 Medium 2024-08-26
CVE-2024-43354 WordPress myCred plugin <= 2.7.2 - PHP Object Injection vulnerability CWE-502 9.8 Critical 2024-08-19
CVE-2024-43353 WordPress myCred plugin <= 2.7.2 - Cross Site Scripting (XSS) vulnerability CWE-79 6.5 Medium 2024-08-18
CVE-2024-32711 WordPress myCred plugin <= 2.6.3 - Cross Site Scripting (XSS) vulnerability CWE-79 6.5 Medium 2024-04-24
CVE-2023-35096 WordPress myCred Plugin <= 2.5 is vulnerable to Cross Site Request Forgery (CSRF) CWE-352 5.4 Medium 2023-07-17
CVE-2022-1092 myCred < 2.4.4 - Subscriber+ Import/Export to Email Address Disclosure 4.3 - 2022-04-25
CVE-2022-0363 myCred < 2.4.4 - Subscriber+ Arbitrary Post Creation 4.3 - 2022-04-25
CVE-2022-0287 Mycred < 2.4.4.1 - Subscriber+ User E-mail Addresses Disclosure 4.3 - 2022-04-25

All 18 known CVE vulnerabilities affecting myCred with full Chinese analysis, references, and POCs where available.