Stored Cross-Site Scripting Vulnerability in myCred Plugin for WordPress
CVE-2026-8607
6.4MEDIUM
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 17 June 2026
What is CVE-2026-8607?
The myCred plugin for WordPress is susceptible to a Stored Cross-Site Scripting vulnerability through the 'wrap' shortcode attribute due to inadequate input sanitization and output escaping. Authenticated attackers with contributor-level access or higher can exploit this flaw to inject arbitrary scripts into pages. These scripts will run whenever a user visits the compromised page, potentially leading to unauthorized actions or data exposure.
Affected Version(s)
Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program β myCred 0 <= 3.1