Access Control Vulnerability in myCred New User Approve Plugin by myCred
CVE-2026-28163
5.3MEDIUM
What is CVE-2026-28163?
The myCred New User Approve plugin is susceptible to a missing authorization vulnerability, allowing attackers to exploit incorrectly configured access control security levels. This could lead to unauthorized actions, compromising the integrity of user management. Users of versions from n/a through 3.2.8 are particularly at risk, making it essential for website administrators to review and secure their configurations to prevent exploitation.
Affected Version(s)
New User Approve <= 3.2.8