Impact
The myCred WordPress plugin fails to confirm that the receiver specified in incoming payment gateway notifications matches the merchant account configured by the site. This omission allows an attacker who can send crafted notifications to the gateway’s IPN endpoint to credit any user account with arbitrary amounts of the site’s virtual currency, effectively creating money out of thin air. The weakness undermines the integrity of the virtual economy and can be exploited to inflate balances, bypass limits, and potentially defraud the platform or its users.
Affected Systems
WordPress sites running the myCred plugin before version 3.2.5 are affected. The vulnerability resides in the payment processing module (buyCRED), which handles PayPal IPN messages. Any site that has not upgraded to 3.2.5 or newer remains vulnerable.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity vulnerability. No EPSS data is available, and the issue is not listed in CISA’s KEV catalog. The flaw can be exploited by an unauthenticated attacker who can forge or replay IPN requests to the myCred gateway endpoint; no user credentials or administrative access are required. If the attacker controls a PayPal account used as the notification destination, they can trigger legitimate notifications to the site, making the exploit straightforward. The potential impact on the site's virtual currency economy is significant, while the likelihood of exploitation depends on the visibility and usage of the affected plugin.
OpenCVE Enrichment