CVE-2025-54667: WordPress myCred plugin <= 2.9.4.3 - Race Condition Vulnerability
Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Saad Iqbal myCred allows Leveraging Time-of-Check and Time-of-Use (TOCTOU) Race Conditions. This issue affects myCred: from n/a through 2.9.4.3.
Other sources
Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Saad Iqbal myCred mycred allows Leveraging Time-of-Check and Time-of-Use (TOCTOU) Race Conditions.This issue affects myCred: from n/a through <= 2.9.4.3.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-54667?
CVE-2025-54667 is classified as a critical vulnerability that allows exploitation through race conditions.
How do I fix CVE-2025-54667?
To fix CVE-2025-54667, update your myCred installation to version 2.9.4.4 or later.
What impact does CVE-2025-54667 have on myCred?
CVE-2025-54667 can lead to unauthorized actions or access due to a time-of-check to time-of-use race condition.
Which versions of myCred are affected by CVE-2025-54667?
CVE-2025-54667 affects myCred versions from n/a through 2.9.4.3.
Is CVE-2025-54667 specific to any platform?
CVE-2025-54667 specifically impacts the myCred plugin on WordPress.