📦 Gamipress

by Gamipress

🔍 What is Gamipress?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2023-24000

CRITICAL CVSS 9.8 Oct 31, 2023

This CVE describes an unauthenticated SQL injection vulnerability in the GamiPress WordPress plugin. Attackers can execute arbitrary SQL commands without authentication, potentially compromising the d...

CVE-2024-13495

HIGH CVSS 7.3 Jan 22, 2025

This vulnerability allows unauthenticated attackers to execute arbitrary WordPress shortcodes through the GamiPress plugin's AJAX function. Attackers can potentially inject malicious code, create back...

CVE-2024-13496

HIGH CVSS 7.5 Jan 22, 2025

CVE-2024-13496 is a time-based SQL injection vulnerability in the GamiPress WordPress plugin that allows unauthenticated attackers to extract sensitive database information. All WordPress sites using ...

CVE-2024-13499

HIGH CVSS 7.3 Jan 22, 2025

This vulnerability allows unauthenticated attackers to execute arbitrary WordPress shortcodes through the GamiPress plugin. Attackers can potentially run malicious code, access sensitive data, or take...

CVE-2024-11036

HIGH CVSS 7.3 Nov 19, 2024

This vulnerability allows unauthenticated attackers to execute arbitrary WordPress shortcodes via the gamipress_get_user_earnings AJAX action. All WordPress sites using GamiPress plugin versions up to...

CVE-2024-2505

HIGH CVSS 8.1 Apr 29, 2024

The GamiPress WordPress plugin before version 6.8.9 has a broken access control vulnerability that allows Authors to manipulate requests and grant access to lower-privileged users like Subscribers. Th...

CVE-2024-1799

HIGH CVSS 8.8 Mar 20, 2024

This SQL injection vulnerability in the GamiPress WordPress plugin allows authenticated attackers with contributor-level access or higher to inject malicious SQL queries through the 'achievement_types...

CVE-2023-25697

MEDIUM CVSS 5.4 Jun 19, 2024

This CVE describes a Cross-Site Request Forgery (CSRF) vulnerability in the GamiPress WordPress plugin. It allows attackers to trick authenticated administrators into performing unintended actions, po...