Extension WordPress
Vulnérabilités Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred
Cette page rassemble les failles publiées pour Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred
30 fiches
myCred – Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program <= 3.1 – Authenticated (Contributor+) Stored Cross-Site Scripting via 'wrap' Shortcode Attribute
The Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'wrap' Shortcode Attribute in all versions up to, and including, 3.1 due to insufficient…
*-3.1
3.1.1
16/06/2026
Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred <= 3.0.4 – Authenticated (Subscriber+) Stored Cross-Site Scripting
The Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.0.4 due to insufficient input sanitization and output escaping.…
*-3.0.4
3.0.5
15/05/2026
Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred <= 3.0.3 – Missing Authorization
The Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 3.0.3.…
*-3.0.3
3.0.4
24/04/2026
myCred <= 2.9.7.3 – Authenticated (Contributor+) Stored Cross-Site Scripting via 'mycred_load_coupon' Shortcode
The myCred plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'mycred_load_coupon' shortcode in all versions up to, and including, 2.9.7.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes…
*-2.9.7.3
2.9.7.4
13/02/2026
myCred <= 2.9.7.3 – Missing Authorization
The myCred – Points Management System For Gamification, Ranks, Badges, and Loyalty Program. plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.9.7.3.…
*-2.9.7.3
2.9.7.4
06/02/2026
myCred – Points Management System For Gamification, Ranks, Badges, and Loyalty Program <= 2.9.7.1 – Missing Authorization to Sensitive Information Exposure
The myCred – Points Management System For Gamification, Ranks, Badges, and Loyalty Program plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 2.9.7.1. This is due to the plugin not properly verifying that…
*-2.9.7.1
2.9.7.2
18/12/2025
myCred – Points Management System For Gamification, Ranks, Badges, and Loyalty Program <= 2.9.7 – Missing Authorization to Unauthenticated Withdrawal Request Approval
The myCred – Points Management System For Gamification, Ranks, Badges, and Loyalty Program plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 2.9.7. This is due to the plugin not properly verifying that…
*-2.9.7
2.9.7.1
12/12/2025
myCred – Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program. <= 2.9.7.6 – Authenticated (Contributor+) Stored Cross-Site Scripting
The myCred – Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program. plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.9.7.6 due to insufficient input sanitization and output escaping.…
*-2.9.7.6
3.0
08/11/2025
myCred <= 2.9.4.3 – Authenticated (Subscriber+) Race Condition
The myCred – Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program. plugin for WordPress is vulnerable to a race condition in all versions up to, and including, 2.9.4.3. This makes it possible for authenticated attackers,…
*-2.9.4.3
2.9.4.4
30/07/2025
myCred <= 2.9.4.3 – Authenticated (Contributor+) Stored Cross-Site Scripting
The myCred plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.9.4.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above,…
*-2.9.4.3
2.9.4.4
30/07/2025
myCred <= 2.9.4.2 – Missing Authorization
The myCred – Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program. plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including,…
*-2.9.4.2
2.9.4.3
12/06/2025
myCred <= 2.9.4.2 – Missing Authorization
The myCred – Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program. plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including,…
*-2.9.4.2
2.9.4.3
12/06/2025
myCred – Loyalty Points and Rewards plugin <= 2.7.5.2 – Authenticated (Contributor+) Stored Cross-Site Scripting via mycred_send Shortcode
The myCred – Loyalty Points and Rewards plugin for WordPress and WooCommerce – Give Points, Ranks, Badges, Cashback, WooCommerce rewards, and WooCommerce credits for Gamification plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's mycred_send…
*-2.7.5.2
2.7.6
05/12/2024
myCred <= 2.7.4 – Authenticated (Contributor+) Stored Cross-Site Scripting via mycred_link Shortcode
The myCred – Loyalty Points and Rewards plugin for WordPress and WooCommerce – Give Points, Ranks, Badges, Cashback, WooCommerce rewards, and WooCommerce credits for Gamification plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's mycred_link…
*-2.7.4
2.7.5
07/11/2024
myCred – Loyalty Points and Rewards plugin for WordPress and WooCommerce – Give Points, Ranks, Badges, Cashback, WooCommerce rewards, and WooCommerce credits for Gamification <= 2.7.3 – Missing Authorization to Unauthenticated Database Upgrade
The myCred – Loyalty Points and Rewards plugin for WordPress and WooCommerce – Give Points, Ranks, Badges, Cashback, WooCommerce rewards, and WooCommerce credits for Gamification plugin for WordPress is vulnerable to unauthorized modification of data due to a…
*-2.7.3
2.7.4
24/09/2024
myCred <= 2.7.2 – Authenticated (Contributor+) Stored Cross-Site Scripting
The myCred plugin for WordPress is vulnerable to Stored Cross-Site Scripting via wrapper attribute in versions up to, and including, 2.7.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level…
*-2.7.2
2.7.3
16/08/2024
myCred <= 2.7.2 – Unauthenticated PHP Object Injection
The myCred – Loyalty Points and Rewards plugin for WordPress and WooCommerce – Give Points, Ranks, Badges, Cashback, WooCommerce rewards, and WooCommerce credits for Gamification plugin for WordPress is vulnerable to PHP Object Injection in all versions up…
*-2.7.2
2.7.3
16/08/2024
myCred <= 2.7.2 – Unauthenticated Information Exposure
The myCred – Loyalty Points and Rewards plugin for WordPress and WooCommerce – Give Points, Ranks, Badges, Cashback, WooCommerce rewards, and WooCommerce credits for Gamification plugin for WordPress is vulnerable to Information Exposure in all versions up to,…
*-2.7.2
2.7.3
09/08/2024
myCred – Points, Rewards, Gamification, Ranks, Badges & Loyalty Plugin <= 2.6.3 – Authenticated (Subscriber+) Stored Cross-Site Scripting
The myCred – Points, Rewards, Gamification, Ranks, Badges & Loyalty Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.6.3 due to insufficient input sanitization and output escaping. This makes…
*-2.6.3
2.6.4
22/04/2024
myCred <= 2.6.1 – Authenticated (Contributor+) Stored Cross-Site Scripting
The myCred – Points, Rewards, Gamification, Ranks, Badges & Loyalty Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 2.6.1 due to insufficient input sanitization and…
*-2.6.1
2.6.2
20/11/2023
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.