Description
The Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'wrapper' Shortcode Attribute in all versions up to, and including, 3.2.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Published: 2026-09-09
Score: 6.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross‑Site Scripting enabling arbitrary script execution by authenticated contributor users
Action: Immediate Patch
AI Analysis

Impact

The vulnerability exists in the myCred Points Management System plugin for WordPress, affecting all versions up to and including 3.2.4. The "wrapper" shortcode attribute accepts input that is not properly sanitized or escaped, allowing an attacker with contributor-level or higher authentication to store arbitrary JavaScript in content. Once stored, the script is rendered in every page that includes the shortcode, which executes in the browsers of any visitor to that page. The vulnerability enables the attacker to insert client‑side code that can manipulate the page or carry out malicious actions in the context of the visitor, thereby compromising the integrity of the content delivered. The weakness is classified as CWE‑79, an input validation failure with missing output encoding.

Affected Systems

All installations of the WordPress myCred Points Management System plugin up to and including version 3.2.4 are affected. The plugin is employed on WordPress sites that include the Sell Content addon where the "wrapper" shortcode is available. No other vendors or products are listed as impacted.

Risk and Exploitability

The CVSS score of 6.4 indicates a moderate severity. The attack requires the attacker to first obtain contributor or higher authentication on the WordPress site, so it is not a purely remote exploitation. EPSS is not available, so no current exploitation statistics are provided. The vulnerability is not listed in the CISA KEV catalog. Because the exploit stores scripts in the content, a site administrator who has not yet applied the fix can be compromised once an attacker gains contributor access.

Generated by OpenCVE AI on September 9, 2026 at 10:34 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the myCred plugin to version 3.2.5 or later, which removes the "wrapper" shortcode vulnerability.
  • If an upgrade cannot be performed immediately, tier down contributor-level permissions or disable the Sell Content addon to prevent use of the vulnerable shortcode until a patch is applied.
  • Apply a content sanitization filter, such as enabling the 'sanitize_shortcodes' setting or using a security plugin that removes scripts from post content, to reduce risk.

Generated by OpenCVE AI on September 9, 2026 at 10:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 13 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Saadiqbal
Saadiqbal mycred – Points Management System For Gamification, Ranks, Badges, And Loyalty Program.
Wordpress
Wordpress wordpress
Vendors & Products Saadiqbal
Saadiqbal mycred – Points Management System For Gamification, Ranks, Badges, And Loyalty Program.
Wordpress
Wordpress wordpress

Wed, 09 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 07:45:00 +0000

Type Values Removed Values Added
Description The Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'wrapper' Shortcode Attribute in all versions up to, and including, 3.2.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Title myCred – Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program <= 3.2.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'wrapper' Shortcode Attribute
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

Saadiqbal Mycred – Points Management System For Gamification, Ranks, Badges, And Loyalty Program.
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-09-09T16:02:44.225Z

Reserved: 2026-07-24T17:34:19.630Z

Link: CVE-2026-17149

cve-icon Vulnrichment

Updated: 2026-09-09T15:49:49.643Z

cve-icon NVD

Status : Deferred

Published: 2026-09-09T08:17:19.870

Modified: 2026-09-09T17:17:16.743

Link: CVE-2026-17149

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-13T20:01:58Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')