Extension WordPress

Vulnérabilités Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred, page 2

Cette page rassemble les failles publiées pour Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred, leurs plages de versions affectées et les correctifs signalés dans la base locale.

30Vulnérabilités
0Critiques
30Avec correctif
8,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred

30 fiches

CVE-2023-33999 Moyenne · 6,1
Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred

Freemius SDK <= 2.5.9 – Reflected Cross-Site Scripting via fs_request_get

The Freemius SDK for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘fs_request_get’ function in versions up to, and including, 2.5.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to…

Versions affectées

*-2.5.2

Correctif

2.5.3

Publication

18/07/2023

CVE-2023-35096 Moyenne · 4,3
Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred

myCred <= 2.5 – Cross-Site Request Forgery

The myCred plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.5. This is due to missing nonce validation on the mycred_save_license() function. This makes it possible for unauthenticated attackers to modify…

Versions affectées

[*, 2.5.1)

Correctif

2.5.1

Publication

14/06/2023

Vulnérabilité Moyenne · 6,1
Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred

myCred – Points, Rewards, Gamification, Ranks, Badges & Loyalty Plugin <= 2.4.6.1 – Cross-Site Scripting

The myCred – Points, Rewards, Gamification, Ranks, Badges & Loyalty plugin for WordPress is vulnerable to Cross-Site Scripting via several parameters in versions up to, and including, 2.4.6.1 due to insufficient input sanitization and output escaping. This makes…

Versions affectées

*-2.4.6.1

Correctif

2.4.7

Publication

16/06/2022

CVE-2022-0287 Moyenne · 4,3
Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred

myCred – Points, Rewards, Gamification, Ranks, Badges & Loyalty Plugin <= 2.4.3 – Missing Authorization

The myCred WordPress plugin before 2.4.3.1 does not have any authorisation in place in its mycred-tools-select-user AJAX action, allowing any authenticated user, such as subscriber to call and retrieve all email addresses from the blog

Versions affectées

[*, 2.4.3.1)

Correctif

2.4.3.1

Publication

04/04/2022

CVE-2022-0363 Moyenne · 6,5
Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred

myCred – Points, Rewards, Gamification, Ranks, Badges & Loyalty Plugin <= 2.4.3 – Missing Authorization

The myCred WordPress plugin before 2.4.4 does not have any authorisation and CSRF checks in the mycred-tools-import-export AJAX action, allowing any authenticated users, such as subscribers, to call it and import mycred setup, thus creating badges, managing points…

Versions affectées

[*, 2.4.4)

Correctif

2.4.4

Publication

29/03/2022

CVE-2022-1092 Moyenne · 4,3
Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred

myCred – Points, Rewards, Gamification, Ranks, Badges & Loyalty Plugin <= 2.4.3 – Missing Authorization

The myCred WordPress plugin before 2.4.4 does not have authorisation and CSRF checks in its mycred-tools-import-export AJAX action, allowing any authenticated user to call and and retrieve the list of email address present in the blog

Versions affectées

[*, 2.4.4)

Correctif

2.4.4

Publication

29/03/2022

CVE-2022-4974 Moyenne · 6,3
Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred

Freemius SDK <= 2.4.2 – Missing Authorization Checks

The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions…

Versions affectées

[*, 2.4.3.1)

Correctif

2.4.3.1

Publication

04/03/2022

CVE-2021-25015 Moyenne · 6,1
Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred

myCred – Points, Rewards, Gamification, Ranks, Badges & Loyalty Plugin <= 2.3.2 – Reflected Cross-Site Scripting

The myCred WordPress plugin before 2.4 does not sanitise and escape the search query before outputting it back in the history dashboard page, leading to a Reflected Cross-Site Scripting issue

Versions affectées

*-2.3.2

Correctif

2.4

Publication

27/12/2021

CVE-2021-24755 Élevée · 8,8
Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred

myCred – Points, Rewards, Gamification, Ranks, Badges & Loyalty Plugin <= 2.2 – Subscriber+ SQL Injection

The myCred WordPress plugin before 2.3 does not validate or escape the fields parameter before using it in a SQL statement, leading to an SQL injection exploitable by any authenticated user

Versions affectées

*-2.2

Correctif

2.3

Publication

01/11/2021

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités