PT-2026-84616 · WordPress · Gamipress
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
GamiPress WordPress plugin versions prior to 7.9.9.6
Description
The video watch-tracking functionality does not properly restrict access, enabling users with the Subscriber role to award configured gamification points, achievements, and ranks to any user, including administrators. Additionally, this allows users to accrue these rewards without limit.
Recommendations
Update GamiPress WordPress plugin to version 7.9.9.6 or later.
Exploit
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gamipress