Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred <= 3.0.3 - Missing Authorization
Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred
Minimum safe version
3.0.4
Update to 3.0.4 or later to address 33 fixable vulnerabilities
myCred <= 2.9.7.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'mycred_load_coupon' Shortcode
CVE-2026-27440
myCred <= 2.9.7.3 - Missing Authorization
CVE-2025-12361
CVE-2025-12362
CVE-2025-54668
CVE-2025-54667
CVE-2025-49857
CVE-2025-49872
CVE-2024-11201
Freemius SDK <= 2.4.2 - Missing Authorization Checks
CVE-2024-10187
CVE-2024-8658
CVE-2024-43354
CVE-2024-43353
CVE-2024-43214
CVE-2024-32711
CVE-2023-47853
myCred < 2.4.4 - Reflected Cross-Site Scripting
WordPress myCred Plugin < 2.5.3 is vulnerable to Cross Site Scripting (XSS)
CVE-2023-35096
myCred <= 2.5 - Cross-Site Request Forgery
Freemius SDK <= 2.4.2 - Missing Authorization Checks
myCred – Points, Rewards, Gamification, Ranks, Badges & Loyalty Plugin <= 2.4.6.1 - Cross-Site Scripting
WordPress myCred plugin <= 2.4.3 - Sensitive Information Disclosure vulnerability
WordPress myCred plugin <= 2.4.3 - Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability
CVE-2022-0363
CVE-2022-0287
CVE-2022-1092
CVE-2017-20008
CVE-2021-24755
CVE-2021-25015