{"schema_version":1,"title":"myCred vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 6 vulnerabilities in myCred: 0 in the last 7 days and 3 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-17149, was published on 9 September 2026.","url":"https://junglewise.ai/threats/technologies/mycred","json_url":"https://junglewise.ai/threats/technologies/mycred.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/mycred","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":0,"all_time":6,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":1,"last_90_days":3,"last_365_days":6},"latest":[{"cve":"CVE-2026-17149","cvss":6.4,"epss":0.002,"slug":"cve-2026-17149-wordpress-mycred-stored-xss-in-shortcode-wrapper-attribute","title":"WordPress myCred Stored XSS in shortcode wrapper attribute","severity":"medium","exploited":false,"published_at":"2026-09-09T08:17:19.87+00:00","url":"https://junglewise.ai/threats/cve-2026-17149-wordpress-mycred-stored-xss-in-shortcode-wrapper-attribute"},{"cve":"CVE-2026-15150","cvss":5.3,"epss":0.0016,"slug":"cve-2026-15150-mycred-wordpress-plugin-payment-bypass-via-missing-ipn-receiver","title":"myCred WordPress plugin payment bypass via missing IPN receiver verification","severity":"medium","exploited":false,"published_at":"2026-08-21T12:16:22.963+00:00","url":"https://junglewise.ai/threats/cve-2026-15150-mycred-wordpress-plugin-payment-bypass-via-missing-ipn-receiver"},{"cve":"CVE-2026-61968","cvss":5.4,"slug":"cve-2026-61968-saad-iqbal-mycred-missing-authorization-in-access-control","title":"Saad Iqbal myCred missing authorization in access control","severity":"medium","exploited":false,"published_at":"2026-07-13T10:16:46.813+00:00","url":"https://junglewise.ai/threats/cve-2026-61968-saad-iqbal-mycred-missing-authorization-in-access-control"},{"cve":"CVE-2026-8607","cvss":6.4,"epss":0.0027,"slug":"cve-2026-8607-mycred-wordpress-plugin-stored-xss-in-wrap-shortcode-attribute","title":"myCred WordPress plugin Stored XSS in wrap shortcode attribute","severity":"medium","exploited":false,"published_at":"2026-06-17T13:21:34.59+00:00","url":"https://junglewise.ai/threats/cve-2026-8607-mycred-wordpress-plugin-stored-xss-in-wrap-shortcode-attribute"},{"cve":"CVE-2026-40794","cvss":6.5,"slug":"cve-2026-40794-mycred-broken-access-control-in-wordpress-plugin","title":"myCred broken access control in WordPress plugin","severity":"medium","exploited":false,"published_at":"2026-06-15T21:16:51.783+00:00","url":"https://junglewise.ai/threats/cve-2026-40794-mycred-broken-access-control-in-wordpress-plugin"},{"cve":"CVE-2026-42676","cvss":6.5,"slug":"cve-2026-42676-mycred-stored-cross-site-scripting-in-wordpress-plugin","title":"myCred Stored Cross-Site Scripting in WordPress plugin","severity":"medium","exploited":false,"published_at":"2026-06-01T17:17:00.163+00:00","url":"https://junglewise.ai/threats/cve-2026-42676-mycred-stored-cross-site-scripting-in-wordpress-plugin"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[],"technology":{"hub":true,"name":"myCred","slug":"mycred","vendor":{"name":"myCred","slug":"mycred","url":"https://junglewise.ai/threats/vendors/mycred"},"aliases":[],"category":"library","homepage":"https://mycred.me/","repo_url":"https://github.com/mycred/mycred","description":"An adaptive points management system that allows users to build and manage a broad range of digital rewards including points, badges, and ranks on WordPress sites.","url":"https://junglewise.ai/threats/technologies/mycred"},"most_severe":[{"cve":"CVE-2026-40794","cvss":6.5,"slug":"cve-2026-40794-mycred-broken-access-control-in-wordpress-plugin","title":"myCred broken access control in WordPress plugin","severity":"medium","exploited":false,"published_at":"2026-06-15T21:16:51.783+00:00","url":"https://junglewise.ai/threats/cve-2026-40794-mycred-broken-access-control-in-wordpress-plugin"},{"cve":"CVE-2026-42676","cvss":6.5,"slug":"cve-2026-42676-mycred-stored-cross-site-scripting-in-wordpress-plugin","title":"myCred Stored Cross-Site Scripting in WordPress plugin","severity":"medium","exploited":false,"published_at":"2026-06-01T17:17:00.163+00:00","url":"https://junglewise.ai/threats/cve-2026-42676-mycred-stored-cross-site-scripting-in-wordpress-plugin"},{"cve":"CVE-2026-8607","cvss":6.4,"epss":0.0027,"slug":"cve-2026-8607-mycred-wordpress-plugin-stored-xss-in-wrap-shortcode-attribute","title":"myCred WordPress plugin Stored XSS in wrap shortcode attribute","severity":"medium","exploited":false,"published_at":"2026-06-17T13:21:34.59+00:00","url":"https://junglewise.ai/threats/cve-2026-8607-mycred-wordpress-plugin-stored-xss-in-wrap-shortcode-attribute"},{"cve":"CVE-2026-17149","cvss":6.4,"epss":0.002,"slug":"cve-2026-17149-wordpress-mycred-stored-xss-in-shortcode-wrapper-attribute","title":"WordPress myCred Stored XSS in shortcode wrapper attribute","severity":"medium","exploited":false,"published_at":"2026-09-09T08:17:19.87+00:00","url":"https://junglewise.ai/threats/cve-2026-17149-wordpress-mycred-stored-xss-in-shortcode-wrapper-attribute"},{"cve":"CVE-2026-61968","cvss":5.4,"slug":"cve-2026-61968-saad-iqbal-mycred-missing-authorization-in-access-control","title":"Saad Iqbal myCred missing authorization in access control","severity":"medium","exploited":false,"published_at":"2026-07-13T10:16:46.813+00:00","url":"https://junglewise.ai/threats/cve-2026-61968-saad-iqbal-mycred-missing-authorization-in-access-control"},{"cve":"CVE-2026-15150","cvss":5.3,"epss":0.0016,"slug":"cve-2026-15150-mycred-wordpress-plugin-payment-bypass-via-missing-ipn-receiver","title":"myCred WordPress plugin payment bypass via missing IPN receiver verification","severity":"medium","exploited":false,"published_at":"2026-08-21T12:16:22.963+00:00","url":"https://junglewise.ai/threats/cve-2026-15150-mycred-wordpress-plugin-payment-bypass-via-missing-ipn-receiver"}],"generated_at":"2026-09-26T09:11:00.170868+00:00"}