Race Condition Vulnerability in myCred Plugin by Saad Iqbal
CVE-2025-54667

5.3MEDIUM

Key Information:

Vendor

WordPress

Status
Vendor
CVE Published:
14 August 2025

What is CVE-2025-54667?

The myCred plugin developed by Saad Iqbal is susceptible to a time-of-check time-of-use (TOCTOU) race condition vulnerability. This issue may allow attackers to leverage the disparity in checking conditions and their subsequent use, potentially leading to unauthorized actions on the affected WordPress site. Affected versions include myCred 2.9.4.3 and prior, necessitating immediate attention from site administrators to mitigate risks associated with this flaw.

Affected Version(s)

myCred <= 2.9.4.3

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Esteban Montes Morales (Patchstack Alliance)
.
CVE-2025-54667 : Race Condition Vulnerability in myCred Plugin by Saad Iqbal