plugin

Accredible Certificates Vulnerabilities

4 known security issues reported for the Accredible Certificates WordPress plugin. Most recent disclosed Apr 10, 2025.

2 medium

Running Accredible Certificates on your site? Check whether your installed version is affected.

Scan your site free

Accredible Certificates &amp; Open Badges [accredible-certificates] <= 1.4.9 (unfixed)

unknown

[en] The Accredible Certificates & Open Badges plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby’ parameter in all versions up to, and including, 1.4.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it p...

Affected:
up to 1.4.9
Fix:
No patched version reported
Disclosed:
Apr 10, 2025

CVE-2024-13909 on NVD →

Accredible Certificates & Open Badges <= 1.4.9 - Authenticated (Administrator+) SQL Injection via orderby Parameter

medium

The Accredible Certificates & Open Badges plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby’ parameter in all versions up to, and including, 1.4.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possib...

CVSS:
4.9
Affected:
up to 1.4.9
Fixed in:
1.5.0
Disclosed:
Apr 9, 2025

CVE-2024-13909 on NVD →

Accredible Certificates &amp; Open Badges [accredible-certificates] < 1.4.9

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Accredible Accredible Certificates & Open Badges allows Stored XSS.This issue affects Accredible Certificates & Open Badges: from n/a through 1.4.8.

Affected:
up to 1.4.9
Fixed in:
1.4.9
Disclosed:
Dec 21, 2023

CVE-2023-50827 on NVD →

Accredible Certificates & Open Badges <= 1.4.8 - Authenticated (Administrator+) Stored Cross-Site Scripting via settings

medium

The Accredible Certificates & Open Badges plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.4.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions...

CVSS:
4.4
Affected:
up to 1.4.8
Fixed in:
1.4.9
Disclosed:
Dec 19, 2023

CVE-2023-50827 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database