Description
The myCred WordPress plugin before 2.4.3.1 does not have authorisation and CSRF checks in its mycred-tools-import-export AJAX action, allowing any authenticated user to call and and retrieve the list of email address present in the blog
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-24435 | The myCred WordPress plugin before 2.4.3.1 does not have authorisation and CSRF checks in its mycred-tools-import-export AJAX action, allowing any authenticated user to call and and retrieve the list of email address present in the blog |
References
History
Fri, 17 Oct 2025 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wpexperts
Wpexperts mycred |
|
| CPEs | cpe:2.3:a:wpexperts:mycred:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Mycred
Mycred mycred |
Wpexperts
Wpexperts mycred |
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2024-08-02T23:55:22.825Z
Reserved: 2022-03-25T00:00:00.000Z
Link: CVE-2022-1092
No data.
Status : Modified
Published: 2022-04-25T16:16:08.310
Modified: 2025-10-17T16:52:50.380
Link: CVE-2022-1092
No data.
OpenCVE Enrichment
No data.
EUVD