Description
Missing Authorization vulnerability in Saad Iqbal myCred mycred allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects myCred: from n/a through <= 3.1.2.
Published: 2026-07-13
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a missing authorization flaw in the myCred WordPress plugin that permits attackers to exploit incorrectly configured access control security levels. It allows an attacker to bypass normal user permissions and gain unauthorized access to protected functionality or data. The weakness is categorized as CWE‑862, indicating an authorization failure.

Affected Systems

The issue affects every installation of the myCred plugin version 3.1.2 and earlier by Saad Iqbal. Any WordPress site using these plugin versions is susceptible, regardless of the overall WordPress version.

Risk and Exploitability

The CVSS score of 5.4 indicates a moderate severity. The EPSS score of less than 1% suggests the likelihood of exploitation is low at the time of analysis. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector involves an authenticated user who can interact with the plugin’s endpoints or a user who gains temporary elevated permissions through another vulnerability. Exploitation would enable the attacker to access or modify protected data or perform privileged actions beyond their assigned role.

Generated by OpenCVE AI on August 1, 2026 at 10:14 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the myCred plugin to the latest version (greater than 3.1.2) to receive the authorization fix.
  • Review and tighten WordPress role and capability settings, removing any unnecessary privileges that could be abused through the plugin.
  • If the plugin is not required, deactivate or delete it to eliminate the attack surface.

Generated by OpenCVE AI on August 1, 2026 at 10:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 13 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in Saad Iqbal myCred mycred allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects myCred: from n/a through <= 3.1.2.
Title WordPress myCred plugin <= 3.1.2 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-13T14:19:50.158Z

Reserved: 2026-07-13T06:13:50.885Z

Link: CVE-2026-61968

cve-icon Vulnrichment

Updated: 2026-07-13T14:19:44.539Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T10:15:03Z

Weaknesses