Badgeos is a gamification platform for WordPress that provides badge and achievement management across learning and engagement applications, with a comparatively narrow product footprint. Vulnerabilities affecting the vendor skew toward serious outcomes and frequently acquire public exploit code, while clustering around web-application fundamentals: authorization bypass through user-controlled keys, SQL injection, cross-site request forgery, cross-site scripting, and missing authorization checks that are typical of plugin and CMS-extension ecosystems. Defenders should treat Badgeos disclosures as application-layer priorities for affected WordPress deployments; current severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Badgeos over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-0817CRITICAL The BadgeOS WordPress plugin through 3.7.0 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX action, leading to an SQL Injection exploitable b | May 9, 2022 | 9.8 | 42 | NO | YES |
CVE-2022-2958HIGH The BadgeOS WordPress plugin before 3.7.1.3 does not sanitise and escape parameters before using them in SQL statements via AJAX actions available to any authenticated users, leadi | Sep 19, 2022 | 8.8 | 28 | NO | NO |
CVE-2022-41987HIGH Cross-Site Request Forgery (CSRF) vulnerability in LearningTimes BadgeOS plugin <= 3.7.1.6 versions. | May 25, 2023 | 8.8 | 27 | NO | NO |
CVE-2023-2171MEDIUM The BadgeOS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versions up to, and including, 3.7.1.6 due to insufficient input sani | Aug 31, 2023 | 5.4 | 18 | NO | NO |
CVE-2023-2174MEDIUM The BadgeOS plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the delete_badgeos_log_entries function in versions up to, | Aug 31, 2023 | 4.3 | 15 | NO | NO |
CVE-2023-2173MEDIUM The BadgeOS plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 3.7.1.6. This is due to improper validation and authorization c | Aug 31, 2023 | 4.3 | 15 | NO | NO |
CVE-2023-2172MEDIUM The BadgeOS plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 3.7.1.6. This is due to improper validation and authorization c | Aug 31, 2023 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Badgeos.
Media articles that mention a CVE ID that affects a product developed by Badgeos — matched by CVE ID, not by vendor name.