Pricing
Case studies
Login
Start trial
myCred
Saad Iqbal
Developer
3.0.2
Latest version
10,000
Installations
No date
Last updated
WordPress Plugin
Active VDP
Report vulnerability
Vulnerabilities
Security Policy
Security Contributors
Vulnerability history
0 present
27 patched
8 Mitigation rules
Authenticated (Contributor+) Stored Cross-Site Scripting via 'mycred_load_coupon' Shortcode vulnerability
<= 2.9.7.3
13/02/2026
Broken Access Control vulnerability
<= 2.9.7.3
06/01/2026
Missing Authorization to Sensitive Information Exposure vulnerability
<= 2.9.7.1
18/12/2025
Missing Authorization to Unauthenticated Withdrawal Request Approval vulnerability
<= 2.9.7
13/12/2025
Cross Site Scripting (XSS) vulnerability
<= 2.9.7.6
08/11/2025
Cross Site Scripting (XSS) Vulnerability
<= 2.9.4.3
30/07/2025
Race Condition Vulnerability
<= 2.9.4.3
30/07/2025
Broken Access Control Vulnerability
<= 2.9.4.2
12/06/2025
Broken Access Control Vulnerability
<= 2.9.4.2
12/06/2025
Authenticated (Contributor+) Stored Cross-Site Scripting via mycred_send Shortcode vulnerability
<= 2.7.5.2
05/12/2024
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
<= 2.7.4
07/11/2024
Missing Authorization to Unauthenticated Database Upgrade vulnerability
<= 2.7.3
25/09/2024
PHP Object Injection vulnerability
<= 2.7.2
16/08/2024
Cross Site Scripting (XSS) vulnerability
<= 2.7.2
16/08/2024
Sensitive Data Exposure vulnerability
<= 2.7.2
09/08/2024
Cross Site Scripting (XSS) vulnerability
<= 2.6.3
22/04/2024
Cross Site Scripting (XSS) vulnerability
<= 2.6.1
20/11/2023
Reflected Cross Site Scripting (XSS) vulnerability
< 2.5.3
18/07/2023
Cross Site Request Forgery (CSRF)
<= 2.5
15/06/2023
User E-mail Addresses Disclosure vulnerability
<= 2.4.4
04/04/2022
Arbitrary Post Creation vulnerability
<= 2.4.3
29/03/2022
Import/Export to Email Address Disclosure vulnerability
<= 2.4.3
29/03/2022
Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability
<= 2.4.3
28/02/2022
Sensitive Information Disclosure vulnerability
<= 2.4.3
28/02/2022
Reflected Cross-Site Scripting (XSS) vulnerability
<= 2.3.2
27/12/2021
SQL Injection (SQLi) vulnerability
<= 2.2
01/11/2021
Reflected Cross-Site Scripting (XSS) vulnerability
<= 1.7.7
20/04/2017