VYPR

Gamipress

by WordPress

Source repositories

CVEs (26)

  • CVE-2024-8245MedMay 15, 2025
    risk 0.28cvss 4.3epss 0.00

    The GamiPress WordPress plugin before 1.0.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

  • CVE-2024-30455MedMar 29, 2024
    risk 0.28cvss 4.3epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in GamiPress.This issue affects GamiPress: from n/a through 6.8.5.

  • CVE-2025-13812MedJan 6, 2026
    risk 0.21cvss 4.3epss 0.00

    The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the gamipress_ajax_get_posts and gamipress_ajax_get_users functions in all…

  • CVE-2026-15730MedJul 28, 2026
    risk 0.00cvss 6.4epss 0.00

    The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'heading_size' Shortcode Attribute in all versions up to, and including, 7.9.9.1 due to insufficient input…

  • CVE-2026-59538CriJul 27, 2026
    risk 0.00cvss 9.3epss 0.00

    Unauthenticated SQL Injection in GamiPress <= 7.9.7 versions.

  • CVE-2026-13450MedJul 9, 2026
    risk 0.00cvss 5.3epss 0.01

    The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 7.9.4 via the 'access' parameter due to missing validation on a user…

Page 2 of 2