Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress — Vulnerabilities & Security Advisories 11

All 11 CVE vulnerabilities found in GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress, with AI-generated Chinese analysis, references, and POCs.

Vendor: rubengc

CVE IDTitleCVSSSeverityPublished
CVE-2026-16091 GamiPress <= 7.9.9.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'gamipress_rank' Shortcode CWE-79 6.4 Medium2026-08-01
CVE-2026-16090 GamiPress <= 7.9.9.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via gamipress_achievement Shortcode CWE-79 6.4 Medium2026-08-01
CVE-2026-15730 GamiPress <= 7.9.9.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'heading_size' Shortcode Attribute CWE-79 6.4 Medium2026-07-28
CVE-2026-13450 GamiPress <= 7.9.4 - Insecure Direct Object Reference to Unauthenticated Sensitive Information Disclosure via 'access' Parameter CWE-639 5.3 Medium2026-07-09
CVE-2025-13812 GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress <= 7.6.1 - Missing Authorization to Authenticated (Subscriber+) Information Exposure CWE-862 4.3 Medium2026-01-06
CVE-2024-13496 GamiPress <= 7.3.1 - Unauthenticated SQL Injection via orderby Parameter CWE-89 7.5 High2025-01-22
CVE-2024-13499 GamiPress <= 7.2.1 - Unauthenticated Arbitrary Shortcode Execution via gamipress_do_shortcode() Function CWE-94 7.3 High2025-01-22
CVE-2024-13495 GamiPress <= 7.2.1 - Unauthenticated Arbitrary Shortcode Execution via gamipress_ajax_get_logs Function CWE-94 7.3 High2025-01-22
CVE-2024-11036 GamiPress – The #1 gamification plugin to reward points, achievements, badges & ranks in WordPress <= 7.1.5 - Unauthenticated Arbitrary Shortcode Execution via gamipress_get_user_earnings CWE-94 7.3 High2024-11-19
CVE-2024-2783 GamiPress – The #1 gamification plugin to reward points, achievements, badges & ranks in WordPress <= 6.9.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode CWE-79 6.4 Medium2024-04-09
CVE-2024-1799 GamiPress – The #1 gamification plugin to reward points, achievements, badges & ranks in WordPress <= 6.8.6 - Authenticated (Contributor+) SQL Injection via Shortcode CWE-89 8.8 High2024-03-20

All 11 known CVE vulnerabilities affecting GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress with full Chinese analysis, references, and POCs where available.