Impact
The vulnerability is a missing authorization condition in the Saad Iqbal myCred plugin, which lets attackers bypass configured access control levels. Because of this flaw, even users with limited privileges can access functions that should be restricted. This is a classic broken access control issue (CWE‑862). The impact allows unauthorized access to content, settings, or data managed by myCred.
Affected Systems
Saad Iqbal myCred plugin for WordPress, all releases from the first version through and including 2.9.4.2, are affected. Any WordPress site installing this plugin at a version ≤ 2.9.4.2 could be vulnerable.
Risk and Exploitability
CVSS score is 4.3, indicating moderate risk. The EPSS score is < 1 %, signifying a very low probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog, and there is currently no evidence of reported exploitation. Attackers would most likely need to probe the plugin’s endpoints or trigger privileged actions, implying a web‑application attack vector; no additional elevated privileges or pre‑existing conditions are explicitly required beyond the presence of a vulnerable installation.
OpenCVE Enrichment
EUVD