PT-2025-51087 · WordPress · Mycred

Rafshanzani Suhada

·

Publicado

2025-12-13

·

Atualizado

2025-12-13

·

CVE-2025-12362

CVSS v3.1

5.3

Média

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions myCred – Points Management System For Gamification, Ranks, Badges, and Loyalty Program plugin for WordPress versions through 2.9.7
Description The software does not properly verify user authorization, allowing unauthenticated attackers to perform actions without proper access. Specifically, attackers can approve withdrawal requests, modify user point balances, and manipulate the payment processing system. This is achieved through the cashcred pay now API endpoint.
Recommendations Update to version 2.9.7.1 or later.

Correção

Missing Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-12362

Produtos afetados

Mycred