CVE-2017-20008: Mycred
Medium severity, CVSS 6.1. EPSS: 0.9% chance of exploitation in the next 30 days.
The myCred WordPress plugin before 1.7.8 does not sanitise and escape the user parameter before outputting it back in the Points Log admin dashboard, leading to a Reflected Cross-Site Scripting
Affected products
- Mycred Mycred: before 1.7.8 (fixed in 1.7.8)
Published 2021-11-29. Last modified 2026-06-17.