Extension WordPress

Vulnérabilités Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred

Cette page rassemble les failles publiées pour Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred, leurs plages de versions affectées et les correctifs signalés dans la base locale.

30Vulnérabilités
0Critiques
30Avec correctif
8,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred

30 fiches

CVE-2026-8607 Moyenne · 6,4
Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred

myCred – Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program <= 3.1 – Authenticated (Contributor+) Stored Cross-Site Scripting via 'wrap' Shortcode Attribute

The Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'wrap' Shortcode Attribute in all versions up to, and including, 3.1 due to insufficient…

Versions affectées

*-3.1

Correctif

3.1.1

Publication

16/06/2026

CVE-2026-42676 Moyenne · 6,4
Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred

Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred <= 3.0.4 – Authenticated (Subscriber+) Stored Cross-Site Scripting

The Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.0.4 due to insufficient input sanitization and output escaping.…

Versions affectées

*-3.0.4

Correctif

3.0.5

Publication

15/05/2026

CVE-2026-40794 Moyenne · 4,3
Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred

Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred <= 3.0.3 – Missing Authorization

The Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 3.0.3.…

Versions affectées

*-3.0.3

Correctif

3.0.4

Publication

24/04/2026

CVE-2026-0550 Moyenne · 6,4
Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred

myCred <= 2.9.7.3 – Authenticated (Contributor+) Stored Cross-Site Scripting via 'mycred_load_coupon' Shortcode

The myCred plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'mycred_load_coupon' shortcode in all versions up to, and including, 2.9.7.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes…

Versions affectées

*-2.9.7.3

Correctif

2.9.7.4

Publication

13/02/2026

CVE-2026-24951 Moyenne · 4,3
Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred

myCred <= 2.9.7.3 – Missing Authorization

The myCred – Points Management System For Gamification, Ranks, Badges, and Loyalty Program. plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.9.7.3.…

Versions affectées

*-2.9.7.3

Correctif

2.9.7.4

Publication

06/02/2026

CVE-2025-12361 Moyenne · 4,3
Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred

myCred – Points Management System For Gamification, Ranks, Badges, and Loyalty Program <= 2.9.7.1 – Missing Authorization to Sensitive Information Exposure

The myCred – Points Management System For Gamification, Ranks, Badges, and Loyalty Program plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 2.9.7.1. This is due to the plugin not properly verifying that…

Versions affectées

*-2.9.7.1

Correctif

2.9.7.2

Publication

18/12/2025

CVE-2025-12362 Moyenne · 5,3
Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred

myCred – Points Management System For Gamification, Ranks, Badges, and Loyalty Program <= 2.9.7 – Missing Authorization to Unauthenticated Withdrawal Request Approval

The myCred – Points Management System For Gamification, Ranks, Badges, and Loyalty Program plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 2.9.7. This is due to the plugin not properly verifying that…

Versions affectées

*-2.9.7

Correctif

2.9.7.1

Publication

12/12/2025

CVE-2026-27440 Moyenne · 6,4
Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred

myCred – Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program. <= 2.9.7.6 – Authenticated (Contributor+) Stored Cross-Site Scripting

The myCred – Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program. plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.9.7.6 due to insufficient input sanitization and output escaping.…

Versions affectées

*-2.9.7.6

Correctif

3.0

Publication

08/11/2025

CVE-2025-54667 Moyenne · 4,3
Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred

myCred <= 2.9.4.3 – Authenticated (Subscriber+) Race Condition

The myCred – Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program. plugin for WordPress is vulnerable to a race condition in all versions up to, and including, 2.9.4.3. This makes it possible for authenticated attackers,…

Versions affectées

*-2.9.4.3

Correctif

2.9.4.4

Publication

30/07/2025

CVE-2025-54668 Moyenne · 6,4
Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred

myCred <= 2.9.4.3 – Authenticated (Contributor+) Stored Cross-Site Scripting

The myCred plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.9.4.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above,…

Versions affectées

*-2.9.4.3

Correctif

2.9.4.4

Publication

30/07/2025

CVE-2025-49857 Moyenne · 4,3
Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred

myCred <= 2.9.4.2 – Missing Authorization

The myCred – Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program. plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including,…

Versions affectées

*-2.9.4.2

Correctif

2.9.4.3

Publication

12/06/2025

CVE-2025-49872 Moyenne · 5,3
Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred

myCred <= 2.9.4.2 – Missing Authorization

The myCred – Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program. plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including,…

Versions affectées

*-2.9.4.2

Correctif

2.9.4.3

Publication

12/06/2025

CVE-2024-11201 Moyenne · 6,4
Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred

myCred – Loyalty Points and Rewards plugin <= 2.7.5.2 – Authenticated (Contributor+) Stored Cross-Site Scripting via mycred_send Shortcode

The myCred – Loyalty Points and Rewards plugin for WordPress and WooCommerce – Give Points, Ranks, Badges, Cashback, WooCommerce rewards, and WooCommerce credits for Gamification plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's mycred_send…

Versions affectées

*-2.7.5.2

Correctif

2.7.6

Publication

05/12/2024

CVE-2024-10187 Moyenne · 6,4
Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred

myCred <= 2.7.4 – Authenticated (Contributor+) Stored Cross-Site Scripting via mycred_link Shortcode

The myCred – Loyalty Points and Rewards plugin for WordPress and WooCommerce – Give Points, Ranks, Badges, Cashback, WooCommerce rewards, and WooCommerce credits for Gamification plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's mycred_link…

Versions affectées

*-2.7.4

Correctif

2.7.5

Publication

07/11/2024

CVE-2024-8658 Moyenne · 5,3
Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred

myCred – Loyalty Points and Rewards plugin for WordPress and WooCommerce – Give Points, Ranks, Badges, Cashback, WooCommerce rewards, and WooCommerce credits for Gamification <= 2.7.3 – Missing Authorization to Unauthenticated Database Upgrade

The myCred – Loyalty Points and Rewards plugin for WordPress and WooCommerce – Give Points, Ranks, Badges, Cashback, WooCommerce rewards, and WooCommerce credits for Gamification plugin for WordPress is vulnerable to unauthorized modification of data due to a…

Versions affectées

*-2.7.3

Correctif

2.7.4

Publication

24/09/2024

CVE-2024-43353 Moyenne · 6,4
Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred

myCred <= 2.7.2 – Authenticated (Contributor+) Stored Cross-Site Scripting

The myCred plugin for WordPress is vulnerable to Stored Cross-Site Scripting via wrapper attribute in versions up to, and including, 2.7.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level…

Versions affectées

*-2.7.2

Correctif

2.7.3

Publication

16/08/2024

CVE-2024-43354 Élevée · 8,1
Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred

myCred <= 2.7.2 – Unauthenticated PHP Object Injection

The myCred – Loyalty Points and Rewards plugin for WordPress and WooCommerce – Give Points, Ranks, Badges, Cashback, WooCommerce rewards, and WooCommerce credits for Gamification plugin for WordPress is vulnerable to PHP Object Injection in all versions up…

Versions affectées

*-2.7.2

Correctif

2.7.3

Publication

16/08/2024

CVE-2024-43214 Moyenne · 5,3
Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred

myCred <= 2.7.2 – Unauthenticated Information Exposure

The myCred – Loyalty Points and Rewards plugin for WordPress and WooCommerce – Give Points, Ranks, Badges, Cashback, WooCommerce rewards, and WooCommerce credits for Gamification plugin for WordPress is vulnerable to Information Exposure in all versions up to,…

Versions affectées

*-2.7.2

Correctif

2.7.3

Publication

09/08/2024

CVE-2024-32711 Moyenne · 5,4
Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred

myCred – Points, Rewards, Gamification, Ranks, Badges & Loyalty Plugin <= 2.6.3 – Authenticated (Subscriber+) Stored Cross-Site Scripting

The myCred – Points, Rewards, Gamification, Ranks, Badges & Loyalty Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.6.3 due to insufficient input sanitization and output escaping. This makes…

Versions affectées

*-2.6.3

Correctif

2.6.4

Publication

22/04/2024

CVE-2023-47853 Moyenne · 6,4
Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred

myCred <= 2.6.1 – Authenticated (Contributor+) Stored Cross-Site Scripting

The myCred – Points, Rewards, Gamification, Ranks, Badges & Loyalty Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 2.6.1 due to insufficient input sanitization and…

Versions affectées

*-2.6.1

Correctif

2.6.2

Publication

20/11/2023

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités