Showing 2 vulnerabilities on this page for mycred

Signals CISA KEV Ransomware Nuclei
wpexperts vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

WordPress myCred plugin <= 2.7.2 - PHP Object Injection vulnerability

Deserialization of Untrusted Data vulnerability in Saad Iqbal myCred mycred.This issue affects myCred: from n/a through <= 2.7.2.

CWE-502Aug 19, 2024
CVSS9.8v3.1EPSS0.528%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

myCred < 2.3 - Subscriber+ SQL Injection

The myCred WordPress plugin before 2.3 does not validate or escape the fields parameter before using it in a SQL statement, leading to an SQL injection exploitable by any authenticated user

CWE-89Nov 29, 2021
CVSS8.8v3.1EPSS1.32%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX