Extension WordPress
Vulnérabilités BadgeOS
Cette page rassemble les failles publiées pour BadgeOS, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de BadgeOS
8 fiches
BadgeOS <= 3.7.1.6 – Missing Authorization
The BadgeOS plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on multiple functions in versions up to, and including, 3.7.1.6. This makes it possible for authenticated attackers, with subscriber-level access…
*-3.7.1.6
Non indiqué
07/11/2023
BadgeOS <= 3.7.1.6 – Authenticated (Subscriber+) Insecure Direct Object Reference to Arbitrary Post Deletion
The BadgeOS plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 3.7.1.6. This is due to improper validation and authorization checks within the badgeos_delete_step_ajax_handler, badgeos_delete_award_step_ajax_handler, badgeos_delete_deduct_step_ajax_handler, and badgeos_delete_rank_req_step_ajax_handler functions. This makes…
*-3.7.1.6
Non indiqué
05/07/2023
BadgeOS <= 3.7.1.6 – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
The BadgeOS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versions up to, and including, 3.7.1.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible…
*-3.7.1.6
Non indiqué
05/07/2023
BadgeOS <= 3.7.1.6 – Missing Authorization in delete_badgeos_log_entries
The BadgeOS plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the delete_badgeos_log_entries function in versions up to, and including, 3.7.1.6. This makes it possible for authenticated attackers, with subscriber-level…
*-3.7.1.6
Non indiqué
05/07/2023
BadgeOS <= 3.7.1.6 – Authenticated (Subscriber+) Insecure Direct Object Reference to Arbitrary Post Title Overwrite
The BadgeOS plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 3.7.1.6. This is due to improper validation and authorization checks within the badgeos_update_steps_ajax_handler, badgeos_update_award_steps_ajax_handler, badgeos_update_deduct_steps_ajax_handler, and badgeos_update_ranks_req_steps_ajax_handler functions. This makes…
*-3.7.1.6
Non indiqué
05/07/2023
BadgeOS <= 3.7.1.6 – Cross-Site Request Forgery
The BadgeOS plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.7.1.6. This is due to missing or incorrect nonce validation on one or more functions. This makes it possible for unauthenticated…
*-3.7.1.6
Non indiqué
18/04/2023
BadgeOS <= 3.7.1.2 – Authenticated (Subscriber+) SQL Injection
The BadgeOS plugin for WordPress is vulnerable to SQL Injection via some of its ajax actions in versions up to, and including, 3.7.1.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on…
*-3.7.1.2
3.7.1.3
23/08/2022
BadgeOS <= 3.7.0 – Unauthenticated SQL Injection
The BadgeOS WordPress plugin through 3.7.0 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX action, leading to an SQL Injection exploitable by unauthenticated users
*-3.7.0
3.7.1
13/04/2022
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.