VYPR

Gamipress

by WordPress

Source repositories

CVEs (24)

  • CVE-2025-13812MedJan 6, 2026
    risk 0.21cvss 4.3epss 0.00

    The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the gamipress_ajax_get_posts and gamipress_ajax_get_users functions in all…

  • CVE-2026-15730MedJul 28, 2026
    risk 0.00cvss 6.4epss 0.00

    The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'heading_size' Shortcode Attribute in all versions up to, and including, 7.9.9.1 due to insufficient input…

  • CVE-2026-59538CriJul 27, 2026
    risk 0.00cvss 9.3epss 0.00

    Unauthenticated SQL Injection in GamiPress <= 7.9.7 versions.

  • CVE-2026-13450MedJul 9, 2026
    risk 0.00cvss 5.3epss 0.00

    The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 7.9.4 via the 'access' parameter due to missing validation on a user…

Page 2 of 2