Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in myCred allows Stored XSS.

This issue affects myCred: from n/a through 3.0.4.
Published: 2026-06-01
Score: 6.5 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Improper sanitization of user input in the myCred WordPress plugin enables attackers to store malicious scripts directly in the database, which are then rendered when pages load. The primary effect is the ability to execute arbitrary client‑side code in the browsers of site visitors, potentially leading to session hijacking, credential theft, or defacement of content. The vulnerability is a classic stored XSS flaw (CWE-79).

Affected Systems

The flaw exists in all releases of the myCred plugin up to and including version 3.0.4. Users running any older or the referenced versions on WordPress installations are affected until the plugin is updated to 3.0.5 or later.

Risk and Exploitability

The CVSS score of 6.5 indicates a medium‑to‑high risk if an attacker can inject scripts. No EPSS data is available, so the current exploitation likelihood is unknown, and the vulnerability is not listed in the CISA KEV catalog. Attackers must have access to a form or input that stores data through the plugin, a condition typically satisfied on publicly exposed sites. Should successful exploitation occur, the attacker can execute code in the context of any user visiting the affected page.

Generated by OpenCVE AI on June 1, 2026 at 18:42 UTC.

Remediation

Vendor Solution

Update the WordPress myCred Plugin to the latest available version (at least 3.0.5).


OpenCVE Recommended Actions

  • Upgrade the WordPress myCred plugin to version 3.0.5 or newer to eliminate the stored XSS flaw.
  • If an immediate upgrade is not feasible, disable or secure input fields that the plugin uses until the patch is applied, preventing new malicious data from being stored.
  • After applying the update, inspect or purge any previously stored content that may contain injected scripts to remove residual threats.

Generated by OpenCVE AI on June 1, 2026 at 18:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 01 Jun 2026 19:00:00 +0000

Type Values Removed Values Added
First Time appeared Mycred
Mycred mycred
Wordpress
Wordpress wordpress
Vendors & Products Mycred
Mycred mycred
Wordpress
Wordpress wordpress

Mon, 01 Jun 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 01 Jun 2026 17:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in myCred allows Stored XSS. This issue affects myCred: from n/a through 3.0.4.
Title WordPress myCred plugin <= 3.0.4 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Mycred Mycred
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-06-01T17:07:22.055Z

Reserved: 2026-04-29T09:04:52.624Z

Link: CVE-2026-42676

cve-icon Vulnrichment

Updated: 2026-06-01T17:07:16.981Z

cve-icon NVD

Status : Deferred

Published: 2026-06-01T17:17:00.163

Modified: 2026-06-01T17:57:16.380

Link: CVE-2026-42676

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-01T18:45:34Z

Weaknesses