← WordPress Vulnerabilities
WordPress security by component

GamiPress

GamiPress is a WordPress component with 21 published CVE records in this archive. The latest tracked vulnerability was published Jul 28, 2026; the highest CVE/CNA score is 9.3.

Plugin slug: gamipress

CVE-2026-15730: GamiPress contributors can inject script through a shortcode heading

GamiPress through 7.9.9.1 does not validate the heading_size attribute handled by gamipress_points_types_shortcode(). A Contributor can store a crafted [gamipress_points_types] shortcode whose inert text survives WordPress save-time filtering; GamiPress then uses heading_size while generating HTML at render time, producing executable markup for visitors to the page. The CNA record does not disclose the downstream template function that emits the heading. Version 7.9.9.2 applies gamipress_sanitize_title_size_option() to heading_size before rendering.

PublishedJul 28, 2026
Known safe version7.9.9.2
Safe version
Jul 28, 2026 CVE-2026-15730
GamiPress contributors can inject script through a shortcode heading
GamiPress through 7.9.9.1 does not validate the heading_size attribute handled by gamipress_points_types_shortcode(). A Contributor can store a crafted [gamipress_points_types] shortcode whose inert text survives WordPress save-time filtering; GamiPress then uses heading_size while generating HTML at render time, producing executable markup for visitors to the page. The CNA record does not disclose the downstream template function that emits the heading. Version 7.9.9.2 applies gamipress_sanitize_title_size_option() to heading_size before rendering.
7.9.9.2
CVE6.4
NVDPending
Jul 27, 2026 CVE-2026-59538
GamiPress permits unauthenticated SQL injection
GamiPress through 7.9.7 lets an unauthenticated attacker supply input that reaches an SQL statement without safe parameterization. Exploitation can interact with the WordPress database and potentially read or alter data available to the database user. The Patchstack CNA record does not disclose the endpoint, action, parameter, query or vulnerable function.
7.9.8
CVE9.3
NVDPending
Jul 09, 2026 CVE-2026-13450
GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress: A security weakness
GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 7.9.4.
> 7.9.4
CVE5.3
NVDPending
Jun 15, 2026 CVE-2026-48874
GamiPress: SQL injection
GamiPress is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data. The published affected range is n/a through 7.8.7.
7.8.8
CVE8.5
NVDPending
May 25, 2026 CVE-2026-24546
GamiPress: A security weakness
GamiPress is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 7.6.3.
7.6.4
CVE5.3
NVDPending
Mar 13, 2026 CVE-2026-32420
GamiPress: Cross-site request forgery
GamiPress is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE5.4
NVDPending
Jun 06, 2025 CVE-2025-49326
GamiPress: SQL injection
GamiPress is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE7.6
NVDPending
May 07, 2025 CVE-2025-47508
GamiPress: Filesystem traversal
GamiPress is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVE7.5
NVDPending
Jan 22, 2025 CVE-2024-13499
The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in: A security weakness
The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE7.3
NVD7.3
Jan 22, 2025 CVE-2024-13496
GamiPress – Gamification plugin to reward points, achievements, badges & ranks in: SQL injection
GamiPress – Gamification plugin to reward points, achievements, badges & ranks in is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE7.5
NVD7.5
Jan 22, 2025 CVE-2024-13495
The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in: A security weakness
The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE7.3
NVD7.3
Nov 19, 2024 CVE-2024-11036
The GamiPress – The #1 gamification plugin to reward points, achievements, badges & ranks in: A security weakness
The GamiPress – The #1 gamification plugin to reward points, achievements, badges & ranks in is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE7.3
NVD9.8
Jun 19, 2024 CVE-2023-25697
GamiPress: Cross-site request forgery
GamiPress is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE5.4
NVD6.3
Apr 29, 2024 CVE-2024-2505
GamiPress: A security weakness
GamiPress is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE8.1
NVDPending
Apr 09, 2024 CVE-2024-2783
GamiPress – The #1 gamification plugin to reward points, achievements, badges & ranks in: Cross-site scripting
GamiPress – The #1 gamification plugin to reward points, achievements, badges & ranks in is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Mar 29, 2024 CVE-2024-30455
GamiPress: Cross-site request forgery
GamiPress is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVD4.3
Mar 20, 2024 CVE-2024-2460
GamiPress – Button: Cross-site scripting
GamiPress – Button is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVD5.4
Mar 20, 2024 CVE-2024-1799
GamiPress – The #1 gamification plugin to reward points, achievements, badges & ranks in: SQL injection
GamiPress – The #1 gamification plugin to reward points, achievements, badges & ranks in is affected by SQL injection. Exploitation requires at least contributor-level access. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE8.8
NVDPending
Dec 19, 2023 CVE-2023-25715
GamiPress – The #1 gamification plugin to reward points, achievements, badges & ranks in WordPress: A security weakness
GamiPress – The #1 gamification plugin to reward points, achievements, badges & ranks in WordPress is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.4
NVD6.5
Oct 31, 2023 CVE-2023-24000
GamiPress: SQL injection
GamiPress is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE8.2
NVD9.8
Feb 06, 2023 CVE-2023-0154
GamiPress: Cross-site scripting
GamiPress is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.4
NVD5.4