VendorsWPExpertsmycredall versions
Vulnerabilities

WPExperts myCred

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

7CVEs
CVE-2021-24755
myCred < 2.3 - Subscriber+ SQL Injection
Published 2021-11-29 · Modified
8.8EPSS 0.014
CVE-2023-35096
WordPress myCred Plugin <= 2.5 is vulnerable to Cross Site Request Forgery (CSRF)
Published 2023-07-17 · Modified
8.8EPSS 0.002
CVE-2023-47853
WordPress myCred Plugin <= 2.6.1 is vulnerable to Cross Site Scripting (XSS)
Published 2023-11-30 · Modified
6.5EPSS 0.004
CVE-2024-43214
WordPress myCred plugin <= 2.7.2 - Sensitive Data Exposure vulnerability
Published 2024-08-26 · Modified
5.3EPSS 0.003
CVE-2022-0287
Mycred < 2.4.4.1 - Subscriber+ User E-mail Addresses Disclosure
Published 2022-04-25 · Modified
4.3EPSS 0.008
CVE-2022-1092
myCred < 2.4.4 - Subscriber+ Import/Export to Email Address Disclosure
Published 2022-04-25 · Modified
4.3EPSS 0.004
CVE-2022-0363
myCred < 2.4.4 - Subscriber+ Arbitrary Post Creation
Published 2022-04-25 · Modified
4.3EPSS 0.003