BadgeOS < 3.7.1.3 - Subscriber+ SQLi
25Vexday Risk Score
Prioritize patching. It exploitation observed by VulnCheck.
ssvc Attendepss 1.1%
from disclosure to weapon
Published on NVDSep 19
VulnCheck+424d
exploitation probability
1.1%top 39% of all CVEs
observed exploitation
yesVulnCheck
The BadgeOS WordPress plugin before 3.7.1.3 does not sanitise and escape parameters before using them in SQL statements via AJAX actions available to any authenticated users, leading to SQL Injections
Affected products
Unknown · BadgeOS