Project Subscriptions
No advisories yet.
Solution
Update the WordPress myCred plugin to the latest available version (at least 3.0).
Workaround
No workaround given by the vendor.
Tue, 24 Mar 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 24 Mar 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Saad Iqbal myCred mycred allows Stored XSS.This issue affects myCred: from n/a through <= 2.9.7.6. | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in myCred mycred allows Stored XSS.This issue affects myCred: from n/a through 2.9.7.6. |
| References |
|
Fri, 20 Feb 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Fri, 20 Feb 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Saadiqbal
Saadiqbal mycred Wordpress Wordpress wordpress |
|
| Vendors & Products |
Saadiqbal
Saadiqbal mycred Wordpress Wordpress wordpress |
Thu, 19 Feb 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Saad Iqbal myCred mycred allows Stored XSS.This issue affects myCred: from n/a through <= 2.9.7.6. | |
| Title | WordPress myCred plugin <= 2.9.7.6 - Cross Site Scripting (XSS) vulnerability | |
| Weaknesses | CWE-79 | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Patchstack
Published:
Updated: 2026-03-24T10:27:33.521Z
Reserved: 2026-02-19T09:52:39.682Z
Link: CVE-2026-27440
Updated: 2026-02-20T16:47:47.216Z
Status : Awaiting Analysis
Published: 2026-02-19T21:18:33.367
Modified: 2026-03-24T11:16:22.990
Link: CVE-2026-27440
No data.
OpenCVE Enrichment
Updated: 2026-02-20T09:54:01Z