Extension WordPress

Vulnérabilités GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress

Cette page rassemble les failles publiées pour GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress, leurs plages de versions affectées et les correctifs signalés dans la base locale.

19Vulnérabilités
1Critiques
19Avec correctif
9,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress

19 fiches

CVE-2026-13450 Moyenne · 5,3
GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress

GamiPress <= 7.9.4 – Insecure Direct Object Reference to Unauthenticated Sensitive Information Disclosure via 'access' Parameter

The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 7.9.4 via the 'access' parameter due to…

Versions affectées

*-7.9.4

Correctif

7.9.5

Publication

08/07/2026

CVE-2026-48874 Moyenne · 6,5
GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress

GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress <= 7.8.7 – Authenticated (Subscriber+) SQL Injection

The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 7.8.7 due to insufficient escaping on the user supplied parameter…

Versions affectées

*-7.8.7

Correctif

7.8.8

Publication

02/06/2026

CVE-2026-24546 Moyenne · 5,3
GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress

GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress <= 7.6.3 – Missing Authorization

The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 7.6.3.…

Versions affectées

*-7.6.3

Correctif

7.6.4

Publication

25/05/2026

CVE-2026-32420 Moyenne · 4,3
GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress

GamiPress <= 7.6.6 – Cross-Site Request Forgery

The GamiPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 7.6.6. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to…

Versions affectées

*-7.6.6

Correctif

7.6.7

Publication

26/02/2026

CVE-2025-13812 Moyenne · 4,3
GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress

GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress <= 7.6.1 – Missing Authorization to Authenticated (Subscriber+) Information Exposure

The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the gamipress_ajax_get_posts and gamipress_ajax_get_users functions in all…

Versions affectées

*-7.6.1

Correctif

7.6.2

Publication

05/01/2026

CVE-2025-49326 Moyenne · 4,9
GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress

GamiPress <= 7.4.5 – Authenticated (Administrator+) SQL Injection

The GamiPress plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 7.4.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes…

Versions affectées

*-7.4.5

Correctif

7.4.6

Publication

05/06/2025

CVE-2025-47508 Élevée · 8,8
GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress

GamiPress <= 7.3.7 – Authenticated (Contributor+) Local File Inclusion

The GamiPress plugin for WordPress is vulnerable to Local File Inclusion via the gamipress_logs_shortcode() function in versions up to, and including, 7.3.7. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute…

Versions affectées

*-7.3.7

Correctif

7.3.8

Publication

07/05/2025

CVE-2024-13499 Élevée · 7,3
GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress

GamiPress <= 7.2.1 – Unauthenticated Arbitrary Shortcode Execution via gamipress_do_shortcode() Function

The The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is vulnerable to arbitrary shortcode execution via gamipress_do_shortcode() function in all versions up to, and including, 7.2.1. This is due…

Versions affectées

*-7.2.1

Correctif

7.2.2

Publication

21/01/2025

CVE-2024-13495 Élevée · 7,3
GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress

GamiPress <= 7.2.1 – Unauthenticated Arbitrary Shortcode Execution via gamipress_ajax_get_logs Function

The The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is vulnerable to arbitrary shortcode execution via the gamipress_ajax_get_logs() function in all versions up to, and including, 7.2.1. This is…

Versions affectées

*-7.2.1

Correctif

7.2.2

Publication

21/01/2025

CVE-2024-13496 Élevée · 7,5
GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress

GamiPress <= 7.3.1 – Unauthenticated SQL Injection via orderby Parameter

The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby’ parameter in all versions up to, and including, 7.3.1 due to insufficient…

Versions affectées

*-7.3.1

Correctif

7.3.2

Publication

21/01/2025

CVE-2024-11036 Élevée · 7,3
GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress

GamiPress – The #1 gamification plugin to reward points, achievements, badges & ranks in WordPress <= 7.1.5 – Unauthenticated Arbitrary Shortcode Execution via gamipress_get_user_earnings

The The GamiPress – The #1 gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is vulnerable to arbitrary shortcode execution via gamipress_get_user_earnings AJAX action in all versions up to, and including, 7.1.5.…

Versions affectées

*-7.1.5

Correctif

7.1.6

Publication

18/11/2024

CVE-2024-30455 Moyenne · 4,3
GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress

GamiPress <= 6.8.5 – Cross-Site Request Forgery

The GamiPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.8.5. This is due to missing or incorrect nonce validation. This makes it possible for unauthenticated attackers to perform an unauthorized…

Versions affectées

*-6.8.5

Correctif

6.8.6

Publication

28/03/2024

CVE-2024-2783 Moyenne · 6,4
GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress

GamiPress – The #1 gamification plugin to reward points, achievements, badges & ranks in WordPress <= 6.9.0 – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

The GamiPress – The #1 gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 6.9.0 due…

Versions affectées

*-6.9.0

Correctif

6.9.1

Publication

27/03/2024

CVE-2024-1799 Élevée · 8,8
GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress

GamiPress – The #1 gamification plugin to reward points, achievements, badges & ranks in WordPress <= 6.8.6 – Authenticated (Contributor+) SQL Injection via Shortcode

The GamiPress – The #1 gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is vulnerable to SQL Injection via the 'achievement_types' attribute of the gamipress_earnings shortcode in all versions up to, and…

Versions affectées

*-6.8.6

Correctif

6.8.7

Publication

19/03/2024

CVE-2023-25697 Moyenne · 4,3
GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress

GamiPress <= 2.5.6 – Cross-Site Request Forgery to User Earnings Deletion

The GamiPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.5.6. This is due to missing or incorrect nonce validation on the bulk_delete function. This makes it possible for unauthenticated attackers…

Versions affectées

*-2.5.6

Correctif

2.5.7

Publication

14/02/2023

CVE-2023-24000 Critique · 9,8
GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress

GamiPress <= 2.5.7 – Unauthenticated SQL Injection

The GamiPress plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.5.7 due to insufficient escaping on the user supplied parameter '$qv[$field_id]' and lack of sufficient preparation on the existing SQL query. This…

Versions affectées

*-2.5.7

Correctif

2.5.7.1

Publication

14/02/2023

CVE-2023-25715 Moyenne · 4,3
GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress

GamiPress <= 2.5.6 – Missing Authorization to User Points Updates

The GamiPress plugin for WordPress is vulnerable to unauthorized modification of user data due to a missing capability check on the gamipress_ajax_profile_update_user_points function in versions up to, and including, 2.5.6. This makes it possible for authenticated attackers with…

Versions affectées

*-2.5.6

Correctif

2.5.7

Publication

13/02/2023

Vulnérabilité Moyenne · 5,4
GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress

GamiPress <= 2.5.0 – Cross-Site Request Forgery

The GamiPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.5.0. This is due to missing or incorrect nonce validation on the delete function. This makes it possible for unauthenticated attackers…

Versions affectées

*-2.5.0

Correctif

2.5.1

Publication

12/01/2023

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités