CVE-2025-54668: WordPress myCred plugin <= 2.9.4.3 - Cross Site Scripting (XSS) Vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Saad Iqbal myCred allows Stored XSS. This issue affects myCred: from n/a through 2.9.4.3.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Saad Iqbal myCred mycred allows Stored XSS.This issue affects myCred: from n/a through <= 2.9.4.3.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-54668?
CVE-2025-54668 is classified as a high severity vulnerability due to its potential for stored cross-site scripting (XSS) attacks.
How do I fix CVE-2025-54668?
To fix CVE-2025-54668, update the myCred plugin to the latest version that is not affected by this vulnerability.
What happens if my site is vulnerable to CVE-2025-54668?
If your site is vulnerable to CVE-2025-54668, attackers can exploit it to inject malicious scripts, leading to unauthorized actions and data exposure.
Who is affected by CVE-2025-54668?
CVE-2025-54668 affects users of the myCred plugin for WordPress, specifically versions up to and including 2.9.4.3.
Is there a patch for CVE-2025-54668?
Yes, a patch is available in the newer versions of the myCred plugin beyond version 2.9.4.3, which address the vulnerability.