Junglewise Threat Intelligence

CVE-2026-28163: myCred New User Approve broken access control vulnerability

CVE-2026-28163 · Severity: medium · CVSS 5.3 · Published 2026-08-20

Vendors: myCred.

Executive brief

The myCred New User Approve WordPress plugin contains a broken access control flaw that allows unauthenticated users to access pages and perform actions they should not be permitted to perform. Attackers can exploit misconfigured access controls to view restricted data or perform unauthorized administrative actions, potentially compromising user accounts and site integrity.

Technical details

The vulnerability is a broken access control issue (CWE-639) in the New User Approve WordPress plugin versions up to 3.2.8. The plugin fails to properly validate user permissions before granting access to sensitive pages and functions. An unauthenticated attacker can leverage this vulnerability to bypass authorization checks and access or modify restricted functionality without authentication. The flaw was patched in version 3.2.9. No active exploitation in the wild has been reported at the time of disclosure.

Affected products

  • myCred New User Approve through 3.2.8

Timeline

  • 2026-07-18: disclosed: Reported by Austin Ginder
  • 2026-08-20: advisory: Published by Patchstack
  • 2026-08-20: patched: Fix available in version 3.2.9

References