PT-2025-52437 · WordPress · Mycred

Rafshanzani Suhada

·

Published

2025-12-19

·

Updated

2025-12-19

·

CVE-2025-12361

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions myCred – Points Management System For Gamification, Ranks, Badges, and Loyalty Program versions up to and including 2.9.7.1
Description The software does not properly verify user authorization, allowing authenticated attackers with Subscriber-level access or higher to retrieve sensitive user information. Specifically, attackers can access user IDs, display names, and email addresses of all users on the site through the get bank accounts API endpoint. Passwords are not exposed.
Recommendations Versions prior to 2.9.7.1 should be updated.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-12361

Affected Products

Mycred