Accredible Certificates & Open Badges
Accredible Certificates & Open Badges has 2 disclosed vulnerabilities in the WordSec catalog, reported between 2023 and 2025; all 2 are fixed as of September 2026. Their average CVSS score is 4.7, and the most serious one scores 4.9 out of 10.
The most common weakness is Cross-Site Scripting, behind 1 of the records (50%). Other recurring categories include SQL Injection.
Every one of the 2 issues recorded for Accredible Certificates & Open Badges has a vendor fix available, so running the current release closes all known holes.
2 independent researchers contributed these findings, one record each. Accredible Certificates & Open Badges is installed on roughly 90 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.8.8.
CVE-2024-13909Accredible Certificates & Open Badges <= 1.4.9 - Authenticated (Administrator+) SQL Injection via orderby Parameter
Read the full analysisVulnerability Records

Accredible Certificates & Open Badges
Author
accredible
The Accredible platform enables organizations to create, manage and distribute digital credentials as digital certificates, open badges and blockchain credentials. An example digital certificate and badge can be viewed here: https://www.credential.net/10000005 This plugin enables you to issue dynamic, digital certificates or open badges on your WordPress instance. A video walkthrough of the plugin can be viewed here: https://youtu.be/s5krPN6GvTY Benefits of digital credentials: Every time your recipients share their credentials, your brand spreads across the web. View analytics on your alumni. Create a directory of your graduates. Unlimited certificate and badge designs. Easy sharing, exporting and printing. Make sure people can’t lie about taking your course. Example Output
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C