Extension WordPress
Vulnérabilités Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred, page 2
Cette page rassemble les failles publiées pour Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred
30 fiches
Freemius SDK <= 2.5.9 – Reflected Cross-Site Scripting via fs_request_get
The Freemius SDK for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘fs_request_get’ function in versions up to, and including, 2.5.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to…
*-2.5.2
2.5.3
18/07/2023
myCred <= 2.5 – Cross-Site Request Forgery
The myCred plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.5. This is due to missing nonce validation on the mycred_save_license() function. This makes it possible for unauthenticated attackers to modify…
[*, 2.5.1)
2.5.1
14/06/2023
myCred – Points, Rewards, Gamification, Ranks, Badges & Loyalty Plugin <= 2.4.6.1 – Cross-Site Scripting
The myCred – Points, Rewards, Gamification, Ranks, Badges & Loyalty plugin for WordPress is vulnerable to Cross-Site Scripting via several parameters in versions up to, and including, 2.4.6.1 due to insufficient input sanitization and output escaping. This makes…
*-2.4.6.1
2.4.7
16/06/2022
myCred – Points, Rewards, Gamification, Ranks, Badges & Loyalty Plugin <= 2.4.3 – Missing Authorization
The myCred WordPress plugin before 2.4.3.1 does not have any authorisation in place in its mycred-tools-select-user AJAX action, allowing any authenticated user, such as subscriber to call and retrieve all email addresses from the blog
[*, 2.4.3.1)
2.4.3.1
04/04/2022
myCred – Points, Rewards, Gamification, Ranks, Badges & Loyalty Plugin <= 2.4.3 – Missing Authorization
The myCred WordPress plugin before 2.4.4 does not have any authorisation and CSRF checks in the mycred-tools-import-export AJAX action, allowing any authenticated users, such as subscribers, to call it and import mycred setup, thus creating badges, managing points…
[*, 2.4.4)
2.4.4
29/03/2022
myCred – Points, Rewards, Gamification, Ranks, Badges & Loyalty Plugin <= 2.4.3 – Missing Authorization
The myCred WordPress plugin before 2.4.4 does not have authorisation and CSRF checks in its mycred-tools-import-export AJAX action, allowing any authenticated user to call and and retrieve the list of email address present in the blog
[*, 2.4.4)
2.4.4
29/03/2022
Freemius SDK <= 2.4.2 – Missing Authorization Checks
The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions…
[*, 2.4.3.1)
2.4.3.1
04/03/2022
myCred – Points, Rewards, Gamification, Ranks, Badges & Loyalty Plugin <= 2.3.2 – Reflected Cross-Site Scripting
The myCred WordPress plugin before 2.4 does not sanitise and escape the search query before outputting it back in the history dashboard page, leading to a Reflected Cross-Site Scripting issue
*-2.3.2
2.4
27/12/2021
myCred – Points, Rewards, Gamification, Ranks, Badges & Loyalty Plugin <= 2.2 – Subscriber+ SQL Injection
The myCred WordPress plugin before 2.3 does not validate or escape the fields parameter before using it in a SQL statement, leading to an SQL injection exploitable by any authenticated user
*-2.2
2.3
01/11/2021
myCred Plugin <= 1.7.7 – Reflected Cross-Site Scripting
The myCred WordPress plugin before 1.7.8 does not sanitise and escape the user parameter before outputting it back in the Points Log admin dashboard, leading to a Reflected Cross-Site Scripting
[*, 1.7.8)
1.7.8
20/04/2017
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.