Executive brief
The myCred plugin for WordPress, which is used to manage points and rewards programs, contains a security flaw in its access control system. This vulnerability allows logged-in users to bypass intended security levels and perform actions they should not be authorized to do. This could lead to unauthorized modifications of the points system or disruption of the rewards program's integrity.
Technical details
A Missing Authorization (CWE-862) vulnerability exists in the myCred plugin for WordPress through version 3.1.2. The flaw resides in the way the plugin handles access control security levels, failing to properly verify user permissions for certain actions. An authenticated attacker with low-level privileges can exploit this to bypass intended restrictions and perform unauthorized operations. The issue is addressed in version 3.2.0.
Affected products
- Saad Iqbal myCred <= 3.1.2
Timeline
- 2026-07-13: advisory
- 2026-07-13: disclosed
- 3.2.0: patched