plugin

Badgeos Vulnerabilities

8 known security issues reported for the Badgeos WordPress plugin. Most recent disclosed Nov 7, 2023.

1 critical 1 high 6 medium

Running Badgeos on your site? Check whether your installed version is affected.

Scan your site free

BadgeOS <= 3.7.1.6 - Missing Authorization

medium

The BadgeOS plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on multiple functions in versions up to, and including, 3.7.1.6. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform actions such as listing users

CVSS:
4.3
Affected:
up to 3.7.1.6
Fix:
No patched version reported
Disclosed:
Nov 7, 2023

CVE-2023-47647 on NVD →

BadgeOS <= 3.7.1.6 - Authenticated (Subscriber+) Insecure Direct Object Reference to Arbitrary Post Deletion

medium

The BadgeOS plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 3.7.1.6. This is due to improper validation and authorization checks within the badgeos_delete_step_ajax_handler, badgeos_delete_award_step_ajax_handler, badgeos_delete_deduct_step_ajax_handler, and badg...

CVSS:
6.5
Affected:
up to 3.7.1.6
Fix:
No patched version reported
Disclosed:
Jul 5, 2023

CVE-2023-2173 on NVD →

BadgeOS <= 3.7.1.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

medium

The BadgeOS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versions up to, and including, 3.7.1.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and abov...

CVSS:
5.4
Affected:
up to 3.7.1.6
Fix:
No patched version reported
Disclosed:
Jul 5, 2023

CVE-2023-2171 on NVD →

BadgeOS <= 3.7.1.6 - Authenticated (Subscriber+) Insecure Direct Object Reference to Arbitrary Post Title Overwrite

medium

The BadgeOS plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 3.7.1.6. This is due to improper validation and authorization checks within the badgeos_update_steps_ajax_handler, badgeos_update_award_steps_ajax_handler, badgeos_update_deduct_steps_ajax_handler, and b...

CVSS:
4.3
Affected:
up to 3.7.1.6
Fix:
No patched version reported
Disclosed:
Jul 5, 2023

CVE-2023-2172 on NVD →

BadgeOS <= 3.7.1.6 - Missing Authorization in delete_badgeos_log_entries

medium

The BadgeOS plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the delete_badgeos_log_entries function in versions up to, and including, 3.7.1.6. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to delete the plugi...

CVSS:
4.3
Affected:
up to 3.7.1.6
Fix:
No patched version reported
Disclosed:
Jul 5, 2023

CVE-2023-2174 on NVD →

BadgeOS <= 3.7.1.6 - Cross-Site Request Forgery

medium

The BadgeOS plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.7.1.6. This is due to missing or incorrect nonce validation on one or more functions. This makes it possible for unauthenticated attackers to perform actions including modifying badge settings for posts via...

CVSS:
4.3
Affected:
up to 3.7.1.6
Fix:
No patched version reported
Disclosed:
Apr 18, 2023

CVE-2022-41987 on NVD →

BadgeOS <= 3.7.1.2 - Authenticated (Subscriber+) SQL Injection

high

The BadgeOS plugin for WordPress is vulnerable to SQL Injection via some of its ajax actions in versions up to, and including, 3.7.1.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subsc...

CVSS:
8.8
Affected:
up to 3.7.1.2
Fixed in:
3.7.1.3
Disclosed:
Aug 23, 2022

CVE-2022-2958 on NVD →

BadgeOS <= 3.7.0 - Unauthenticated SQL Injection

critical

The BadgeOS WordPress plugin through 3.7.0 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX action, leading to an SQL Injection exploitable by unauthenticated users

CVSS:
9.8
Affected:
up to 3.7.0
Fixed in:
3.7.1
Disclosed:
Apr 13, 2022

CVE-2022-0817 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database