CVE-2022-0287

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
25/04/2022
Last modified:
17/10/2025

Description

The myCred WordPress plugin before 2.4.4.1 does not have any authorisation in place in its mycred-tools-select-user AJAX action, allowing any authenticated user, such as subscriber to call and retrieve all email addresses from the blog

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:wpexperts:mycred:*:*:*:*:*:wordpress:*:* 2.4.4.1 (excluding)