cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forbadgearoo badgearoo

Direction: ascending
May 17, 2025

Badgearoo # CVE-2024-13828

CVE, Research URL

CVE-2024-13828

Application

Badgearoo

Date
May 16, 2025
Research Description
The Badgearoo WordPress plugin through 1.0.14 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
Affected versions
max 1.0.14.
Status
vulnerable
May 19, 2025

Badgearoo # CVE-2025-1033

CVE, Research URL

CVE-2025-1033

Application

Badgearoo

Date
May 16, 2025
Research Description
The Badgearoo WordPress plugin through 1.0.14 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
Affected versions
max 1.0.14.
Status
vulnerable