Extension WordPress
Vulnérabilités GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress
Cette page rassemble les failles publiées pour GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress
19 fiches
GamiPress <= 7.9.4 – Insecure Direct Object Reference to Unauthenticated Sensitive Information Disclosure via 'access' Parameter
The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 7.9.4 via the 'access' parameter due to…
*-7.9.4
7.9.5
08/07/2026
GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress <= 7.8.7 – Authenticated (Subscriber+) SQL Injection
The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 7.8.7 due to insufficient escaping on the user supplied parameter…
*-7.8.7
7.8.8
02/06/2026
GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress <= 7.6.3 – Missing Authorization
The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 7.6.3.…
*-7.6.3
7.6.4
25/05/2026
GamiPress <= 7.6.6 – Cross-Site Request Forgery
The GamiPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 7.6.6. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to…
*-7.6.6
7.6.7
26/02/2026
GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress <= 7.6.1 – Missing Authorization to Authenticated (Subscriber+) Information Exposure
The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the gamipress_ajax_get_posts and gamipress_ajax_get_users functions in all…
*-7.6.1
7.6.2
05/01/2026
GamiPress <= 7.4.5 – Authenticated (Administrator+) SQL Injection
The GamiPress plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 7.4.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes…
*-7.4.5
7.4.6
05/06/2025
GamiPress <= 7.3.7 – Authenticated (Contributor+) Local File Inclusion
The GamiPress plugin for WordPress is vulnerable to Local File Inclusion via the gamipress_logs_shortcode() function in versions up to, and including, 7.3.7. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute…
*-7.3.7
7.3.8
07/05/2025
GamiPress <= 7.2.1 – Unauthenticated Arbitrary Shortcode Execution via gamipress_do_shortcode() Function
The The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is vulnerable to arbitrary shortcode execution via gamipress_do_shortcode() function in all versions up to, and including, 7.2.1. This is due…
*-7.2.1
7.2.2
21/01/2025
GamiPress <= 7.2.1 – Unauthenticated Arbitrary Shortcode Execution via gamipress_ajax_get_logs Function
The The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is vulnerable to arbitrary shortcode execution via the gamipress_ajax_get_logs() function in all versions up to, and including, 7.2.1. This is…
*-7.2.1
7.2.2
21/01/2025
GamiPress <= 7.3.1 – Unauthenticated SQL Injection via orderby Parameter
The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby’ parameter in all versions up to, and including, 7.3.1 due to insufficient…
*-7.3.1
7.3.2
21/01/2025
GamiPress – The #1 gamification plugin to reward points, achievements, badges & ranks in WordPress <= 7.1.5 – Unauthenticated Arbitrary Shortcode Execution via gamipress_get_user_earnings
The The GamiPress – The #1 gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is vulnerable to arbitrary shortcode execution via gamipress_get_user_earnings AJAX action in all versions up to, and including, 7.1.5.…
*-7.1.5
7.1.6
18/11/2024
GamiPress <= 6.8.8 – Broken Access Control
The GamiPress – The #1 gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is vulnerable to broken access control in all versions up to, and including, 6.8.8. This is due to the…
*-6.8.8
6.8.9
08/04/2024
GamiPress <= 6.8.5 – Cross-Site Request Forgery
The GamiPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.8.5. This is due to missing or incorrect nonce validation. This makes it possible for unauthenticated attackers to perform an unauthorized…
*-6.8.5
6.8.6
28/03/2024
GamiPress – The #1 gamification plugin to reward points, achievements, badges & ranks in WordPress <= 6.9.0 – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
The GamiPress – The #1 gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 6.9.0 due…
*-6.9.0
6.9.1
27/03/2024
GamiPress – The #1 gamification plugin to reward points, achievements, badges & ranks in WordPress <= 6.8.6 – Authenticated (Contributor+) SQL Injection via Shortcode
The GamiPress – The #1 gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is vulnerable to SQL Injection via the 'achievement_types' attribute of the gamipress_earnings shortcode in all versions up to, and…
*-6.8.6
6.8.7
19/03/2024
GamiPress <= 2.5.6 – Cross-Site Request Forgery to User Earnings Deletion
The GamiPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.5.6. This is due to missing or incorrect nonce validation on the bulk_delete function. This makes it possible for unauthenticated attackers…
*-2.5.6
2.5.7
14/02/2023
GamiPress <= 2.5.7 – Unauthenticated SQL Injection
The GamiPress plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.5.7 due to insufficient escaping on the user supplied parameter '$qv[$field_id]' and lack of sufficient preparation on the existing SQL query. This…
*-2.5.7
2.5.7.1
14/02/2023
GamiPress <= 2.5.6 – Missing Authorization to User Points Updates
The GamiPress plugin for WordPress is vulnerable to unauthorized modification of user data due to a missing capability check on the gamipress_ajax_profile_update_user_points function in versions up to, and including, 2.5.6. This makes it possible for authenticated attackers with…
*-2.5.6
2.5.7
13/02/2023
GamiPress <= 2.5.0 – Cross-Site Request Forgery
The GamiPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.5.0. This is due to missing or incorrect nonce validation on the delete function. This makes it possible for unauthenticated attackers…
*-2.5.0
2.5.1
12/01/2023
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.