Mycred is a points and gamification plugin for WordPress that operates across a narrow product line centered on the core plugin and its Elementor integration, positioning it within a popular ecosystem for community engagement and user incentive systems. Its observed vulnerability signal centers on web-application input-handling weaknesses, specifically cross-site scripting flaws and authorization bypass conditions that reflect the plugin's exposure to user-supplied content and role-based access control. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mycred over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-25015MEDIUM The myCred WordPress plugin before 2.4 does not sanitise and escape the search query before outputting it back in the history dashboard page, leading to a Reflected Cross-Site Scri | Jan 24, 2022 | 6.1 | 22 | NO | NO |
CVE-2017-20008MEDIUM The myCred WordPress plugin before 1.7.8 does not sanitise and escape the user parameter before outputting it back in the Points Log admin dashboard, leading to a Reflected Cross-S | Nov 29, 2021 | 6.1 | 21 | NO | NO |
CVE-2024-49702MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Saad Iqbal myCred Elementor mycred-for-elementor allows Stored XSS.This issue | Oct 24, 2024 | 5.4 | 17 | NO | NO |
CVE-2024-8658MEDIUM The myCred – Loyalty Points and Rewards plugin for WordPress and WooCommerce – Give Points, Ranks, Badges, Cashback, WooCommerce rewards, and WooCommerce credits for Gamification p | Sep 25, 2024 | 5.3 | 17 | NO | NO |
CVE-2024-10187MEDIUM The myCred – Loyalty Points and Rewards plugin for WordPress and WooCommerce – Give Points, Ranks, Badges, Cashback, WooCommerce rewards, and WooCommerce credits for Gamification p | Nov 8, 2024 | 5.4 | 15 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mycred.
Media articles that mention a CVE ID that affects a product developed by Mycred — matched by CVE ID, not by vendor name.