CVE-2025-49857: WordPress myCred plugin <= 2.9.4.2 - Broken Access Control Vulnerability
Missing Authorization vulnerability in Saad Iqbal myCred mycred allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects myCred: from n/a through <= 2.9.4.2.
Other sources
Missing Authorization vulnerability in WPExperts.io myCred allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects myCred: from n/a through 2.9.4.2.
— NVD
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-49857?
The severity of CVE-2025-49857 is considered high due to its potential to allow unauthorized access to sensitive features.
How do I fix CVE-2025-49857?
To fix CVE-2025-49857, update myCred to a version beyond 2.9.4.2 where the vulnerability has been addressed.
Which versions of myCred are affected by CVE-2025-49857?
CVE-2025-49857 affects myCred versions from n/a to 2.9.4.2.
What type of vulnerability is CVE-2025-49857?
CVE-2025-49857 is a missing authorization vulnerability related to incorrectly configured access control security levels.
Who is the vendor of the affected product for CVE-2025-49857?
The vendor of the affected product, myCred, is WPExperts.