Stored Cross-Site Scripting Vulnerability in myCred Plugin for WordPress
CVE-2026-17149
6.4MEDIUM
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 9 September 2026
What is CVE-2026-17149?
The myCred plugin for WordPress is susceptible to a stored cross-site scripting vulnerability via the 'wrapper' Shortcode Attribute. This issue arises from inadequate input sanitization and output escaping, allowing authenticated attackers with contributor-level access or higher to inject arbitrary web scripts. These scripts could execute whenever a user accesses the compromised page, posing significant risks to users and the integrity of the website.
Affected Version(s)
Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program β myCred 0 <= 3.2.4