SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-15150

MEDIUM · CVSS 5.3 EPSS 0.13%

Source: NVD + CISA KEV + EPSS · Published 2026-08-21 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The myCred WordPress plugin prior to version 3.2.5 is vulnerable due to insufficient verification of payment gateway notifications, enabling attackers to credit arbitrary amounts of in-site currency to any account they control. This could lead to financial loss and manipulation of site resources. WordPress site administrators using the myCred plugin should prioritize updating to the latest version to mitigate this risk.

CVE
CVE-2026-15150
Severity
MEDIUM
CVSS
5.3
EPSS
0.13%
WordPress

Original NVD Description

The myCred WordPress plugin before 3.2.5 does not verify that the receiver of an incoming payment gateway notification matches the site's configured merchant account, allowing unauthenticated attackers to have arbitrary amounts of the site's in-site currency credited to an account by completing a payment for the expected amount to a gateway account they control rather than the site's.