wpexperts Vulnerabilities and Affected Products
Vulnerabilities associated with mycred.
Products
Clear product- mycred2 vulnerabilities
- Post SMTP2 vulnerabilities
- Wholesale For WooCommerce2 vulnerabilities
- wholesale_for_woocommerce2 vulnerabilities
- Password Protected1 vulnerability
- post_smtp1 vulnerability
- post_smtp_mailer1 vulnerability
- user_management1 vulnerability
- wp_secure_maintenance1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2024-43354CRITICAL | WordPress myCred plugin <= 2.7.2 - PHP Object Injection vulnerabilityDeserialization of Untrusted Data vulnerability in Saad Iqbal myCred mycred.This issue affects myCred: from n/a through <= 2.7.2. CWE-502Aug 19, 2024 | CVSS9.8v3.1 | EPSS0.528% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-24755HIGH | myCred < 2.3 - Subscriber+ SQL InjectionThe myCred WordPress plugin before 2.3 does not validate or escape the fields parameter before using it in a SQL statement, leading to an SQL injection exploitable by any authenticated user CWE-89Nov 29, 2021 | CVSS8.8v3.1 | EPSS1.32% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |