
CVE-2023-35096 – WordPress myCred Plugin <= 2.5 is vulnerable to Cross Site Request Forgery (CSRF)
https://notcve.org/view.php?id=CVE-2023-35096
14 Jun 2023 — Cross-Site Request Forgery (CSRF) vulnerability in myCred plugin <= 2.5 versions. The myCred plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.5. This is due to missing nonce validation on the mycred_save_license() function. This makes it possible for unauthenticated attackers to modify the plugin's membership key via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. Cross-Site Request Forgery... • https://patchstack.com/database/vulnerability/mycred/wordpress-mycred-plugin-2-5-cross-site-request-forgery-csrf?_s_id=cve • CWE-352: Cross-Site Request Forgery (CSRF) •

CVE-2022-0287 – Mycred < 2.4.4.1 - Subscriber+ User E-mail Addresses Disclosure
https://notcve.org/view.php?id=CVE-2022-0287
04 Apr 2022 — The myCred WordPress plugin before 2.4.4.1 does not have any authorisation in place in its mycred-tools-select-user AJAX action, allowing any authenticated user, such as subscriber to call and retrieve all email addresses from the blog El plugin myCred de WordPress versiones anteriores a 2.4.3.1, no presenta ninguna autorización en su acción AJAX mycred-tools-select-user, permitiendo a cualquier usuario autenticado, como el suscriptor, llamarlo y recuperar todas las direcciones de correo electrónico del blo... • https://wpscan.com/vulnerability/6cd7cd6d-1cc1-472c-809b-b66389f149b0 • CWE-862: Missing Authorization •

CVE-2022-0363 – myCred < 2.4.4 - Subscriber+ Arbitrary Post Creation
https://notcve.org/view.php?id=CVE-2022-0363
29 Mar 2022 — The myCred WordPress plugin before 2.4.3.1 does not have any authorisation and CSRF checks in the mycred-tools-import-export AJAX action, allowing any authenticated users, such as subscribers, to call it and import mycred setup, thus creating badges, managing points or creating arbitrary posts. El plugin myCred de WordPress versiones anteriores a 2.4.4, no dispone de comprobaciones de autorización y CSRF en la acción AJAX mycred-tools-import-export, permitiendo a cualquier usuario autenticado, como los susc... • https://wpscan.com/vulnerability/a438a951-497c-43cd-822f-1a48d4315191 • CWE-352: Cross-Site Request Forgery (CSRF) CWE-862: Missing Authorization •

CVE-2022-1092 – myCred < 2.4.4 - Subscriber+ Import/Export to Email Address Disclosure
https://notcve.org/view.php?id=CVE-2022-1092
29 Mar 2022 — The myCred WordPress plugin before 2.4.3.1 does not have authorisation and CSRF checks in its mycred-tools-import-export AJAX action, allowing any authenticated user to call and and retrieve the list of email address present in the blog El plugin myCred de WordPress versiones anteriores a 2.4.4, no presenta comprobaciones de autorización y CSRF en su acción AJAX mycred-tools-import-export, permitiendo a cualquier usuario autenticado llamar y recuperar la lista de direcciones de correo electrónico presentes ... • https://wpscan.com/vulnerability/95759d5c-8802-4493-b7e5-7f2bc546af61 • CWE-352: Cross-Site Request Forgery (CSRF) CWE-862: Missing Authorization •

CVE-2021-25015 – myCred < 2.4 - Reflected Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2021-25015
27 Dec 2021 — The myCred WordPress plugin before 2.4 does not sanitise and escape the search query before outputting it back in the history dashboard page, leading to a Reflected Cross-Site Scripting issue El plugin myCred de WordPress versiones anteriores a 2.4, no sanea y escapa de la consulta de búsqueda antes de devolverla a la página del panel de control del historial, conllevando a un problema de tipo Cross-Site Scripting Reflejado • https://plugins.trac.wordpress.org/changeset/2648350/mycred • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2021-24755 – myCred < 2.3 - Subscriber+ SQL Injection
https://notcve.org/view.php?id=CVE-2021-24755
01 Nov 2021 — The myCred WordPress plugin before 2.3 does not validate or escape the fields parameter before using it in a SQL statement, leading to an SQL injection exploitable by any authenticated user El plugin myCred de WordPress versiones anteriores a 2.3, no comprueba ni escapa el parámetro fields antes de usarlo en una sentencia SQL, conllevando a una inyección SQL explotable por cualquier usuario autenticado • https://wpscan.com/vulnerability/01419d03-54d6-413d-9a67-64c63c26d741 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVE-2017-20008 – myCRED < 1.7.8 - Reflected Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2017-20008
20 Apr 2017 — The myCred WordPress plugin before 1.7.8 does not sanitise and escape the user parameter before outputting it back in the Points Log admin dashboard, leading to a Reflected Cross-Site Scripting El plugin myCred de WordPress versiones anteriores a 1.7.8, no sanea y escapa del parámetro user antes de devolverlo al panel de administración del Registro de Puntos, conllevando a un ataque de tipo Cross-Site Scripting Reflejado • https://plugins.trac.wordpress.org/changeset/1639363/mycred • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •