
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-12361 is a Missing Authorization vulnerability in the myCred – Points Management System For Gamification, Ranks, Badges, and Loyalty Program plugin for WordPress. It affects all versions up to and including 2.9.7.1, allowing authenticated attackers with Subscriber-level access or above to retrieve sensitive user information via the get_bank_accounts AJAX action. The vulnerability was published on December 19, 2025, and assigned a CVSS v3.1 base score of 4.3 (Medium) (Wordfence, Red Hat CVE).
The root cause is CWE-862 (Missing Authorization): the plugin fails to properly verify that a requesting user is authorized before executing the get_bank_accounts AJAX action in the banking addon (mycred-service-central.php, around line 172). Any authenticated user — including those with the lowest Subscriber role — can invoke this action over the network with low complexity and no user interaction required. The vulnerable code path is visible in the plugin's source repository, and a patch was applied in changeset 3421768 (Wordfence, WordPress Trac).
Successful exploitation allows an authenticated attacker to enumerate all registered users on the WordPress site, exposing user IDs, display names, and email addresses. While passwords are explicitly not exposed, the harvested data can facilitate targeted phishing, credential stuffing, or account enumeration attacks against the site's user base. The impact is limited to confidentiality (low) with no integrity or availability consequences (Wordfence).
No public exploit code or active in-the-wild exploitation has been reported for this vulnerability. The EPSS score is approximately 0.025% (0.000250), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires at minimum a valid Subscriber-level account on the target WordPress site (Wordfence).
https://target.com/wp-content/plugins/mycred/readme.txt.POST /wp-admin/admin-ajax.php HTTP/1.1
Host: target.com
Cookie: [valid WordPress session cookies]
Content-Type: application/x-www-form-urlencoded
action=get_bank_accounts/wp-admin/admin-ajax.php with the parameter action=get_bank_accounts from a single authenticated session or IP address, especially in rapid succession.admin-ajax.php?action=get_bank_accounts from low-privilege user accounts; unusual access patterns from Subscriber-role accounts.Users should update the myCred plugin to version 2.9.7.2 or later, which includes the authorization fix applied in changeset 3421768. As a temporary workaround, site administrators can disable the myCred Banking addon if it is not required. Restricting new user registrations or limiting Subscriber-level account creation can also reduce the attack surface until patching is possible (Wordfence, WordPress Trac).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."