S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2022-0817 Scanner

CVE-2022-0817 scanner - SQL Injection (SQLi) vulnerability in BadgeOS plugin for WordPress

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.9k
Times Used
continuous scan runs
5.5k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-0817
9.8
CVSS

The BadgeOS WordPress plugin through 3.7.0 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX action, leading to an SQL Injection exploitable by unauthenticated users

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
BadgeOS
3.7.0
Updated Aug 22, 2026View on NVD →
Detail

BadgeOS is a popular WordPress plugin that allows website owners to create custom achievement and reward systems. This plugin enables users to create and manage task and achievement lists, badges, and leaderboards, among other features. The BadgeOS plugin has become a necessary tool for websites that offer gamification or e-learning experiences, as it provides incentives for visitors to engage with the website and stay longer.

Recently, a security vulnerability was discovered in BadgeOS plugin with the CVE-2022-0817 code. This vulnerability allows unauthenticated users to inject arbitrary SQL commands, which the plugin fails to sanitize effectively. A remote attacker can exploit this vulnerability by sending a specifically crafted request to the affected server, allowing them to execute arbitrary code, view, modify, or delete data, and even take control of the entire server.

When this vulnerability is exploited, it can lead to various malicious activities that can cause significant damage to the website and its users. Attackers can obtain sensitive information from the database, such as usernames, passwords, emails, and other critical data. They can also manipulate or delete data, which can result in a complete website shutdown. Additionally, attackers can gain unauthorized access to the server or the network, which potentially gives them unlimited access to various resources.

In conclusion, protecting your digital assets from vulnerabilities is essential to maintain a safe and secure web environment. By using the pro features of s4e.io platform, website owners can stay updated on the latest security threats and vulnerabilities affecting their websites. With features like automatic vulnerability scans, detailed reports, and actionable insights, s4e.io can help businesses stay ahead of the curve in securing their digital assets.

 

REFERENCES

Solution Advice

Website owners who have used BadgeOS plugin should take the necessary precautions to protect their websites from this vulnerability. Here are some ways to safeguard your website:

  • Update the BadgeOS plugin to its latest version as soon as possible.
  • Employ a web application firewall (WAF) to protect your website from known attacks.
  • Use parameterized SQL queries to prevent SQL injection attacks.
  • Implement access control mechanisms to limit the access of unauthenticated and unauthorized users.
  • Backup your website on a regular basis and store it in a secure location.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2022-0817 scanner - SQL Injection (SQLi) vulnerability in BadgeOS plugin for WordPress | S4E