WordPress security by component
GamiPress
Plugin description
GamiPress is a WordPress component with 21 published CVE records in this archive. The latest tracked vulnerability was published Jul 28, 2026; the highest CVE/CNA score is 9.3.
Plugin slug:
gamipressLatest vulnerability
CVE-2026-15730: GamiPress contributors can inject script through a shortcode heading
GamiPress through 7.9.9.1 does not validate the heading_size attribute handled by gamipress_points_types_shortcode(). A Contributor can store a crafted [gamipress_points_types] shortcode whose inert text survives WordPress save-time filtering; GamiPress then uses heading_size while generating HTML at render time, producing executable markup for visitors to the page. The CNA record does not disclose the downstream template function that emits the heading. Version 7.9.9.2 applies gamipress_sanitize_title_size_option() to heading_size before rendering.
| Safe version |
|
||
|---|---|---|---|
| Jul 28, 2026 |
CVE-2026-15730
GamiPress contributors can inject script through a shortcode heading
GamiPress through 7.9.9.1 does not validate the heading_size attribute handled by gamipress_points_types_shortcode(). A Contributor can store a crafted [gamipress_points_types] shortcode whose inert text survives WordPress save-time filtering; GamiPress then uses heading_size while generating HTML at render time, producing executable markup for visitors to the page. The CNA record does not disclose the downstream template function that emits the heading. Version 7.9.9.2 applies gamipress_sanitize_title_size_option() to heading_size before rendering.
|
7.9.9.2 |
CVE6.4
NVDPending
|
| Jul 27, 2026 |
CVE-2026-59538
GamiPress permits unauthenticated SQL injection
GamiPress through 7.9.7 lets an unauthenticated attacker supply input that reaches an SQL statement without safe parameterization. Exploitation can interact with the WordPress database and potentially read or alter data available to the database user. The Patchstack CNA record does not disclose the endpoint, action, parameter, query or vulnerable function.
|
7.9.8 |
CVE9.3
NVDPending
|
| Jul 09, 2026 |
CVE-2026-13450
GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress: A security weakness
GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 7.9.4.
|
> 7.9.4 |
CVE5.3
NVDPending
|
| Jun 15, 2026 |
CVE-2026-48874
GamiPress: SQL injection
GamiPress is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data. The published affected range is n/a through 7.8.7.
|
7.8.8 |
CVE8.5
NVDPending
|
| May 25, 2026 |
CVE-2026-24546
GamiPress: A security weakness
GamiPress is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 7.6.3.
|
7.6.4 |
CVE5.3
NVDPending
|
| Mar 13, 2026 |
CVE-2026-32420
GamiPress: Cross-site request forgery
GamiPress is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE5.4
NVDPending
|
| Jun 06, 2025 |
CVE-2025-49326
GamiPress: SQL injection
GamiPress is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE7.6
NVDPending
|
| May 07, 2025 |
CVE-2025-47508
GamiPress: Filesystem traversal
GamiPress is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
|
See mitigation notes |
CVE7.5
NVDPending
|
| Jan 22, 2025 |
CVE-2024-13499
The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in: A security weakness
The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE7.3
NVD7.3
|
| Jan 22, 2025 |
CVE-2024-13496
GamiPress – Gamification plugin to reward points, achievements, badges & ranks in: SQL injection
GamiPress – Gamification plugin to reward points, achievements, badges & ranks in is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE7.5
NVD7.5
|
| Jan 22, 2025 |
CVE-2024-13495
The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in: A security weakness
The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE7.3
NVD7.3
|
| Nov 19, 2024 |
CVE-2024-11036
The GamiPress – The #1 gamification plugin to reward points, achievements, badges & ranks in: A security weakness
The GamiPress – The #1 gamification plugin to reward points, achievements, badges & ranks in is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE7.3
NVD9.8
|
| Jun 19, 2024 |
CVE-2023-25697
GamiPress: Cross-site request forgery
GamiPress is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE5.4
NVD6.3
|
| Apr 29, 2024 |
CVE-2024-2505
GamiPress: A security weakness
GamiPress is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE8.1
NVDPending
|
| Apr 09, 2024 |
CVE-2024-2783
GamiPress – The #1 gamification plugin to reward points, achievements, badges & ranks in: Cross-site scripting
GamiPress – The #1 gamification plugin to reward points, achievements, badges & ranks in is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Mar 29, 2024 |
CVE-2024-30455
GamiPress: Cross-site request forgery
GamiPress is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE4.3
NVD4.3
|
| Mar 20, 2024 |
CVE-2024-2460
GamiPress – Button: Cross-site scripting
GamiPress – Button is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD5.4
|
| Mar 20, 2024 |
CVE-2024-1799
GamiPress – The #1 gamification plugin to reward points, achievements, badges & ranks in: SQL injection
GamiPress – The #1 gamification plugin to reward points, achievements, badges & ranks in is affected by SQL injection. Exploitation requires at least contributor-level access. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE8.8
NVDPending
|
| Dec 19, 2023 |
CVE-2023-25715
GamiPress – The #1 gamification plugin to reward points, achievements, badges & ranks in WordPress: A security weakness
GamiPress – The #1 gamification plugin to reward points, achievements, badges & ranks in WordPress is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.4
NVD6.5
|
| Oct 31, 2023 |
CVE-2023-24000
GamiPress: SQL injection
GamiPress is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE8.2
NVD9.8
|
| Feb 06, 2023 |
CVE-2023-0154
GamiPress: Cross-site scripting
GamiPress is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.4
NVD5.4
|