CVE-2025-49872: WordPress myCred plugin <= 2.9.4.2 - Broken Access Control Vulnerability
Missing Authorization vulnerability in Saad Iqbal myCred mycred allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects myCred: from n/a through <= 2.9.4.2.
Other sources
Missing Authorization vulnerability in WPExperts.io myCred allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects myCred: from n/a through 2.9.4.2.
— NVD
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-49872?
CVE-2025-49872 is considered a critical vulnerability due to its potential for unauthorized access.
How do I fix CVE-2025-49872?
To fix CVE-2025-49872, update WPExperts.io myCred to version 2.9.4.3 or later.
What functionality is affected by CVE-2025-49872?
CVE-2025-49872 allows access to functionality that is not properly constrained by Access Control Lists (ACLs).
Who is impacted by CVE-2025-49872?
Users of WPExperts.io myCred versions up to and including 2.9.4.2 are impacted by CVE-2025-49872.
What are the potential consequences of CVE-2025-49872?
The potential consequences of CVE-2025-49872 include unauthorized access to restricted functionalities, leading to data breaches or manipulation.