Cross-site Scripting Vulnerability in myCred Plugin by Saad Iqbal
CVE-2025-54668
6.5MEDIUM
What is CVE-2025-54668?
The myCred plugin, developed by Saad Iqbal, is vulnerable to a Cross-site Scripting (XSS) issue allowing attackers to inject malicious scripts. This vulnerability can impact users by storing and executing harmful code on the web page, potentially leading to unauthorized actions. The flaw affects versions of myCred from n/a through 2.9.4.3, making it essential for users to update their installations to mitigate associated risks.
Affected Version(s)
myCred <= 2.9.4.3