PT-2026-67096 · WordPress · Gamipress
CVSS v3.1
6.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
GamiPress versions prior to 7.9.9.2
Description
The GamiPress plugin for WordPress contains a Stored Cross-Site Scripting issue. Authenticated attackers with contributor-level access or higher can inject arbitrary web scripts into pages. This occurs because the
heading size attribute within the gamipress achievement shortcode is not properly sanitized or escaped during output. The standard WordPress wp kses post function fails to neutralize the payload since the value is stored as a shortcode attribute and is only rendered into HTML without escaping at runtime.Recommendations
Update the plugin to a version newer than 7.9.9.1.
As a temporary mitigation, restrict users with contributor-level access from editing pages that utilize the
gamipress achievement shortcode.Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gamipress