CVE-2026-42676: WordPress myCred plugin <= 3.0.4 - Cross Site Scripting (XSS) vulnerability
Published Jun 1, 2026
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in myCred allows Stored XSS.
This issue affects myCred: from n/a through 3.0.4.
Affected Software
1 affected component
Mycred WordPress myCred plugin<=3.0.4
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress myCred pluginto a version that resolves this vulnerability.Fixed in 3.0.5
Event History
Jun 1, 2026
CVE Published
via MITRE·03:17 PM
Data Sourced
via MITRE·03:17 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·05:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-42676?
The severity of CVE-2026-42676 is medium with a score of 6.5.
2
How do I fix CVE-2026-42676?
To fix CVE-2026-42676, update the WordPress myCred plugin to the latest available version, at least 3.0.5.
3
What does CVE-2026-42676 exploit?
CVE-2026-42676 exploits a Cross Site Scripting (XSS) vulnerability in the myCred plugin.
4
Which versions of myCred are affected by CVE-2026-42676?
CVE-2026-42676 affects myCred versions prior to 3.0.4.
5
What type of vulnerability is CVE-2026-42676 classified as?
CVE-2026-42676 is classified as a Cross-site Scripting (XSS) vulnerability.