Access violation vulnerability in BadgeOS 3.7.1.6

The BadgeOS plugin for WordPress, up to and including version 3.7.1.6, is vulnerable to attack. This vulnerability allows an authenticated user with permission levels of at least “subscriber” to delete any post. This is because the plugin does not include proper validation and authorization checks in the functions badgeos_delete_step_ajax_handler, badgeos_delete_award_step_ajax_handler, badgeos_delete_deduct_step_ajax_handler, and badgeos_delete_rank_req_step_ajax_handler.

Detected in:

BadgeOS open vulnerable versions: >= * <= 3.7.1.6

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.