CyberRota Analysis
AI-GeneratedThe myCred WordPress plugin prior to version 3.2.5 is vulnerable due to insufficient verification of payment gateway notifications, enabling attackers to credit arbitrary amounts of in-site currency to any account they control. This could lead to financial loss and manipulation of site resources. WordPress site administrators using the myCred plugin should prioritize updating to the latest version to mitigate this risk.
Original NVD Description
The myCred WordPress plugin before 3.2.5 does not verify that the receiver of an incoming payment gateway notification matches the site's configured merchant account, allowing unauthenticated attackers to have arbitrary amounts of the site's in-site currency credited to an account by completing a payment for the expected amount to a gateway account they control rather than the site's.