CVE-2022-0287

The myCred WordPress plugin before 2.4.4.1 does not have any authorisation in place in its mycred-tools-select-user AJAX action, allowing any authenticated user, such as subscriber to call and retrieve all email addresses from the blog
Configurations

Configuration 1 (hide)

cpe:2.3:a:mycred:mycred:*:*:*:*:*:wordpress:*:*

History

21 Nov 2024, 06:38

Type Values Removed Values Added
References () https://wpscan.com/vulnerability/6cd7cd6d-1cc1-472c-809b-b66389f149b0 - Exploit, Third Party Advisory () https://wpscan.com/vulnerability/6cd7cd6d-1cc1-472c-809b-b66389f149b0 - Exploit, Third Party Advisory

24 Jul 2023, 10:15

Type Values Removed Values Added
Summary The myCred WordPress plugin before 2.4.3.1 does not have any authorisation in place in its mycred-tools-select-user AJAX action, allowing any authenticated user, such as subscriber to call and retrieve all email addresses from the blog The myCred WordPress plugin before 2.4.4.1 does not have any authorisation in place in its mycred-tools-select-user AJAX action, allowing any authenticated user, such as subscriber to call and retrieve all email addresses from the blog

21 Jul 2023, 16:53

Type Values Removed Values Added
CWE CWE-200 CWE-862

03 May 2022, 19:07

Type Values Removed Values Added
References (MISC) https://wpscan.com/vulnerability/6cd7cd6d-1cc1-472c-809b-b66389f149b0 - (MISC) https://wpscan.com/vulnerability/6cd7cd6d-1cc1-472c-809b-b66389f149b0 - Exploit, Third Party Advisory
CVSS v2 : unknown
v3 : unknown
v2 : 4.0
v3 : 4.3
CPE cpe:2.3:a:mycred:mycred:*:*:*:*:*:wordpress:*:*

25 Apr 2022, 16:30

Type Values Removed Values Added
New CVE

Information

Published : 2022-04-25 16:16

Updated : 2024-11-21 06:38


NVD link : CVE-2022-0287

Mitre link : CVE-2022-0287

CVE.ORG link : CVE-2022-0287


JSON object : View

Products Affected

mycred

  • mycred
CWE
CWE-862

Missing Authorization