Cross-site Scripting Vulnerability in myCred Plugin by Saad Iqbal
CVE-2025-54668

6.5MEDIUM

Key Information:

Vendor

WordPress

Status
Vendor
CVE Published:
14 August 2025

What is CVE-2025-54668?

The myCred plugin, developed by Saad Iqbal, is vulnerable to a Cross-site Scripting (XSS) issue allowing attackers to inject malicious scripts. This vulnerability can impact users by storing and executing harmful code on the web page, potentially leading to unauthorized actions. The flaw affects versions of myCred from n/a through 2.9.4.3, making it essential for users to update their installations to mitigate associated risks.

Affected Version(s)

myCred <= 2.9.4.3

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Peter Thaleikis (Patchstack Alliance)
.