CVE-2026-15150: CWE-345 Insufficient Verification of Data Authenticity in myCred
Description
The myCred WordPress plugin versions before 3.2.5 contain a vulnerability where the plugin does not verify that the receiver of an incoming payment gateway notification matches the site's configured merchant account. This flaw allows unauthenticated attackers to credit arbitrary amounts of the site's in-site currency to an account by completing a payment to a gateway account they control instead of the legitimate merchant account.
CVSS v3.1
Score 5.3medium
Affected software
myCred
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-15150 is a vulnerability in the myCred WordPress plugin prior to version 3.2.5. The issue arises from insufficient verification of data authenticity (CWE-345) in payment gateway notifications. Specifically, the plugin fails to confirm that the receiver of a payment notification matches the configured merchant account for the site. This allows unauthenticated attackers to manipulate the system by completing payments to a gateway account they control, resulting in arbitrary crediting of the site's in-site currency to attacker-controlled accounts.
Potential Impact
An attacker can exploit this vulnerability to inflate the balance of in-site currency arbitrarily without proper authorization. This undermines the integrity of the site's currency system and can lead to financial loss or disruption of the site's economy. There is no impact on confidentiality or availability reported. The CVSS v3.1 base score is 5.3 (medium severity), reflecting the ease of exploitation (network, no privileges, no user interaction) and limited impact (integrity only).
Mitigation Recommendations
A fix is available in myCred version 3.2.5 and later. Site administrators should upgrade to version 3.2.5 or newer to remediate this vulnerability. No additional mitigation steps are indicated by the vendor advisory or CVE data.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- WPScan
- Date Reserved
- 2026-07-08T19:34:07.105Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6a883c15acd9273b4916aa29
Added to database: 08/21/2026, 11:52:53 UTC
Last enriched: 09/11/2026, 03:02:45 UTC
Last updated: 10/05/2026, 06:48:14 UTC
Views: 61
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.