Accredible Certificates & Open Badges [accredible-certificates] <= 1.4.9 (unfixed)
unknown
[en] The Accredible Certificates & Open Badges plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby’ parameter in all versions up to, and including, 1.4.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it p...
- Affected:
- up to 1.4.9
- Fix:
- No patched version reported
- Disclosed:
- Apr 10, 2025
CVE-2024-13909 on NVD →
Accredible Certificates & Open Badges <= 1.4.9 - Authenticated (Administrator+) SQL Injection via orderby Parameter
medium
The Accredible Certificates & Open Badges plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby’ parameter in all versions up to, and including, 1.4.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possib...
- CVSS:
- 4.9
- Affected:
- up to 1.4.9
- Fixed in:
- 1.5.0
- Disclosed:
- Apr 9, 2025
CVE-2024-13909 on NVD →
Accredible Certificates & Open Badges [accredible-certificates] < 1.4.9
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Accredible Accredible Certificates & Open Badges allows Stored XSS.This issue affects Accredible Certificates & Open Badges: from n/a through 1.4.8.
- Affected:
- up to 1.4.9
- Fixed in:
- 1.4.9
- Disclosed:
- Dec 21, 2023
CVE-2023-50827 on NVD →
Accredible Certificates & Open Badges <= 1.4.8 - Authenticated (Administrator+) Stored Cross-Site Scripting via settings
medium
The Accredible Certificates & Open Badges plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.4.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions...
- CVSS:
- 4.4
- Affected:
- up to 1.4.8
- Fixed in:
- 1.4.9
- Disclosed:
- Dec 19, 2023
CVE-2023-50827 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database