BadgeOS

BadgeOS is a WordPress plugin that allows website owners to gamify their sites by rewarding users with digital badges, points, and ranks for interacting with the site. Users can create unlimited achievements and ranks using different actions as triggers, and award different point types to users based on the tasks they complete. BadgeOS is the only plugin that allows users to create Open Badge Compliant achievements that contain digital information that can be verified on the site of the badge issuer or using third-party verification tools. The plugin offers a wide range of triggers to award badges, points, and ranks.

This information is sourced from wpvulnerabilities.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Vulnerabilities

  • Access violation vulnerability in BadgeOS 3.7.1.6

    Open

    and viewing their earned badges. BadgeOS is a plugin for WordPress websites. It is vulnerable to data being accessed without permission in versions up to 3.7.1.6. This means that people who have a su...

    Read More
  • Input validation vulnerability in BadgeOS 3.7.1.6

    Open

    The BadgeOS plugin for WordPress is vulnerable to a security risk called Stored Cross-Site Scripting. This means that someone with the correct permissions on the website can inject malicious code int...

    Read More
  • Access violation vulnerability in BadgeOS 3.7.1.6

    Open

    The BadgeOS plugin for WordPress, up to and including version 3.7.1.6, is vulnerable to attack. This vulnerability allows an authenticated user with permission levels of at least "subscriber" to dele...

    Read More
  • Access violation vulnerability in BadgeOS 3.7.1.6

    Open

    The BadgeOS plugin for WordPress is not secure in versions up to 3.7.1.6. This is because it does not properly check if someone is allowed to make changes to posts. An attacker with a certain level o...

    Read More
  • Access violation vulnerability in BadgeOS 3.7.1.6

    Open

    The BadgeOS plugin for WordPress has a security issue in versions up to and including 3.7.1.6. This issue allows attackers who have at least subscriber-level permissions to delete the plugin's log en...

    Read More
  • Input validation vulnerability in BadgeOS 3.7.1.6

    Open

    The BadgeOS plugin for WordPress has a weakness that could allow unauthenticated attackers to make changes to badge settings for posts

    Read More
  • Input validation vulnerability in BadgeOS 3.7.1.2

    Fixed

    The BadgeOS plugin for WordPress has a security weakness in versions up to 3.7.1.2. Someone with an account with subscriber level or higher can exploit this weakness to gain access to sensitive inform...

    Read More
  • Input validation vulnerability in BadgeOS 3.7.0

    Fixed

    Read More