myCred – Loyalty Points and Rewards plugin for WordPress and WooCommerce – Give Points, Ranks, Badges, Cashback, WooCommerce rewards, and WooCommerce credits for Gamification

This information is sourced from wpvulnerabilities.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Vulnerabilities

  • Input validation vulnerability in myCred – Loyalty Points and Rewards plugin for WordPress and WooCommerce – Give Points, Ranks, Badges, Cashback, WooCommerce rewards, and WooCommerce credits for Gamification 2.7.4

    Fixed

    The myCred plugin for WordPress and WooCommerce, which is used to give loyalty points and rewards, has a security vulnerability. This means that attackers who are logged in and have contributor or hi...

    Read More
  • Access violation vulnerability in myCred – Loyalty Points and Rewards plugin for WordPress and WooCommerce – Give Points, Ranks, Badges, Cashback, WooCommerce rewards, and WooCommerce credits for Gamification 2.7.3

    Fixed

    The myCred plugin for WordPress and WooCommerce allows users to earn points, ranks, badges, cashback, and credits for gamification. However, a security weakness has been identified in versions up to ...

    Read More
  • Input validation vulnerability in myCred – Loyalty Points and Rewards plugin for WordPress and WooCommerce – Give Points, Ranks, Badges, Cashback, WooCommerce rewards, and WooCommerce credits for Gamification 2.7.2

    Fixed

    The myCred plugin for WordPress has a security issue that allows attackers to inject harmful code into pages. This can happen when a user with contributor-level access or higher adds a specific attri...

    Read More
  • Input validation vulnerability in myCred – Loyalty Points and Rewards plugin for WordPress and WooCommerce – Give Points, Ranks, Badges, Cashback, WooCommerce rewards, and WooCommerce credits for Gamification 2.7.2

    Fixed

    The myCred – Loyalty Points and Rewards plugin for WordPress and WooCommerce has a security vulnerability that allows attackers to inject a type of code called a PHP Object. This can happen if the ...

    Read More
  • Access violation vulnerability in myCred – Loyalty Points and Rewards plugin for WordPress and WooCommerce – Give Points, Ranks, Badges, Cashback, WooCommerce rewards, and WooCommerce credits for Gamification 2.7.2

    Fixed

    The myCred plugin, used for loyalty points and rewards on WordPress and WooCommerce, has a security vulnerability in all versions up to 2.7.2. This allows anyone without proper authentication to acce...

    Read More
  • Input validation vulnerability in myCred – Points, Rewards, Gamification, Ranks, Badges & Loyalty Plugin 2.6.3

    Fixed

    A popular plugin called myCred for WordPress has a security issue where malicious code can be added to certain pages by attackers with a certain level of access. This can potentially harm users who a...

    Read More
  • Input validation vulnerability in myCred – Points, Rewards, Gamification, Ranks, Badges & Loyalty Plugin 2.6.1

    Fixed

    The myCred – Points, Rewards, Gamification, Ranks, Badges & Loyalty Plugin plugin for WordPress is unsafe and outdated. It has a security vulnerability that could let an attacker with contribut...

    Read More
  • Input validation vulnerability in Freemius SDK 2.5.9 (1072 components affected)

    Fixed

    The Freemius SDK for WordPress is vulnerable to an attack known as Reflected Cross-Site Scripting. This attack is possible because of insufficient security measures in versions of the Freemius SDK up ...

    Read More
  • Input validation vulnerability in myCred – Points, Rewards, Gamification, Ranks, Badges & Loyalty Plugin 2.5.1

    Fixed

    The myCred plugin for WordPress, a version of which is used up to and including version 2.5, has a security vulnerability. An unauthenticated attacker can potentially modify the plugin's membership k...

    Read More
  • Access violation vulnerability in myCred – Points, Rewards, Gamification, Ranks, Badges & Loyalty Plugin 2.4.4

    Fixed

    The myCred WordPress plugin before version 2.4.4 did not have any security measures in place to stop people from using it. This means that any user that was logged in

    Read More
  • Access violation vulnerability in myCred – Points, Rewards, Gamification, Ranks, Badges & Loyalty Plugin 2.4.3.1

    Fixed

    Read More
  • Input validation vulnerability in myCred – Points, Rewards, Gamification, Ranks, Badges & Loyalty Plugin 1.7.8

    Fixed

    The myCred WordPress plugin before version 1.7.8 had a security issue. It did not properly filter what information it showed in the Points Log admin dashboard

    Read More
  • Input validation vulnerability in myCred – Points, Rewards, Gamification, Ranks, Badges & Loyalty Plugin 2.3.2

    Fixed

    Read More
  • Access violation vulnerability in myCred – Points, Rewards, Gamification, Ranks, Badges & Loyalty Plugin 2.4.4

    Fixed

    The myCred plugin for WordPress

    Read More
  • Input validation vulnerability in myCred – Points, Rewards, Gamification, Ranks, Badges & Loyalty Plugin 2.2

    Fixed

    Read More
  • Input validation vulnerability in myCred – Points, Rewards, Gamification, Ranks, Badges & Loyalty Plugin 2.4.6.1

    Fixed

    The myCred plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to 2.4.6.1. This means attackers could inject malicious web scripts into pages that would execute if someone click...

    Read More
  • Access violation vulnerability in Freemius SDK (620 components affected)

    Fixed

    Freemius, a software development kit used by hundreds of WordPress plugin and theme developers, had a security vulnerability in its older versions (up to and including 2.4.2). This vulnerability could...

    Read More