The myCred plugin for WordPress, which is used for gamification, ranks, badges, and loyalty rewards, has a security vulnerability in all versions up to 2.9.4.3. This means that attackers who are logged in with at least Subscriber-level access can perform actions that they are not supposed to be able to do.