| CVE-2026-32420 | WordPress GamiPress plugin <= 7.6.6 - Cross Site Request Forgery (CSRF) vulnerability | Ruben Garcia | GamiPress | 中危 | - | 2026-03-13 11:42:16 | Deep Dive |
| CVE-2025-13812 | GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress <= 7.6.1 - Missing Authorization to Authenticated (Subscriber+) Information Exposure | rubengc | GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress | Medium | 4.3 | 2026-01-06 07:22:13 | Deep Dive |
| CVE-2025-49326 | WordPress GamiPress plugin <= 7.4.5 - SQL Injection Vulnerability | Ruben Garcia | GamiPress | High | 7.6 | 2025-06-06 12:53:56 | Deep Dive |
| CVE-2024-8245 | GamiPress - Reset User <= 1.0.0 - GamiPress User Data Removal via CSRF | Unknown | GamiPress | - | - | 2025-05-15 20:07:14 | Deep Dive |
| CVE-2025-47508 | WordPress GamiPress plugin <= 7.3.7 - Local File Inclusion Vulnerability | Ruben Garcia | GamiPress | High | 7.5 | 2025-05-07 14:20:01 | Deep Dive |
| CVE-2024-13496 | GamiPress <= 7.3.1 - Unauthenticated SQL Injection via orderby Parameter | rubengc | GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress | High | 7.5 | 2025-01-22 11:07:59 | Deep Dive |
| CVE-2024-13499 | GamiPress <= 7.2.1 - Unauthenticated Arbitrary Shortcode Execution via gamipress_do_shortcode() Function | rubengc | GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress | High | 7.3 | 2025-01-22 11:07:58 | Deep Dive |
| CVE-2024-13495 | GamiPress <= 7.2.1 - Unauthenticated Arbitrary Shortcode Execution via gamipress_ajax_get_logs Function | rubengc | GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress | High | 7.3 | 2025-01-22 11:07:57 | Deep Dive |
| CVE-2024-11036 | GamiPress – The #1 gamification plugin to reward points, achievements, badges & ranks in WordPress <= 7.1.5 - Unauthenticated Arbitrary Shortcode Execution via gamipress_get_user_earnings | rubengc | GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress | High | 7.3 | 2024-11-19 11:02:29 | Deep Dive |
| CVE-2023-25697 | WordPress GamiPress plugin <= 2.5.6 - CSRF Leading to Settings Change Vulnerability | GamiPress | GamiPress | Medium | 5.4 | 2024-06-19 14:34:51 | Deep Dive |
| CVE-2024-5536 | GamiPress – Link <= 1.1.4 - Authenticated (Contributor+) Stored Cross-Site Scripting | rubengc | GamiPress – Link | Medium | 6.4 | 2024-06-05 09:32:48 | Deep Dive |
| CVE-2024-2505 | GamiPress < 6.8.9 - Broken Access Control | Unknown | GamiPress | - | - | 2024-04-29 06:00:02 | Deep Dive |
| CVE-2024-2783 | GamiPress – The #1 gamification plugin to reward points, achievements, badges & ranks in WordPress <= 6.9.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode | rubengc | GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress | Medium | 6.4 | 2024-04-09 18:58:56 | Deep Dive |
| CVE-2024-30455 | WordPress GamiPress plugin <= 6.8.5 - Cross Site Request Forgery (CSRF) vulnerability | GamiPress | GamiPress | Medium | 4.3 | 2024-03-29 16:36:37 | Deep Dive |
| CVE-2024-1799 | GamiPress – The #1 gamification plugin to reward points, achievements, badges & ranks in WordPress <= 6.8.6 - Authenticated (Contributor+) SQL Injection via Shortcode | rubengc | GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress | High | 8.8 | 2024-03-20 02:35:42 | Deep Dive |
| CVE-2024-2460 | GamiPress – Button <= 1.0.7 - Authenticated(Contributor+) Stored Cross-Site Scripting via Shortcode | rubengc | GamiPress – Button | Medium | 6.4 | 2024-03-20 02:35:41 | Deep Dive |
| CVE-2023-25715 | WordPress GamiPress Plugin <= 2.5.6 is vulnerable to Broken Access Control | GamiPress | GamiPress – The #1 gamification plugin to reward points, achievements, badges & ranks in WordPress | Medium | 5.4 | 2023-12-19 15:40:16 | Deep Dive |
| CVE-2023-24000 | WordPress GamiPress Plugin <= 2.5.7 is vulnerable to SQL Injection | GamiPress | GamiPress | 超危 | - | 2023-10-31 13:54:07 | Deep Dive |
| CVE-2023-0154 | GamiPress – Vimeo integration < 1.0.9 - Contributor+ Stored XSS | Unknown | GamiPress | 中危 | - | 2023-02-06 19:59:12 | Deep Dive |