GamiPress – Button
GamiPress – Button has 2 disclosed vulnerabilities in the WordSec catalog, reported between 2023 and 2024; all 2 are fixed as of September 2026. Their average CVSS score is 6.4, and the most serious one scores 6.4 out of 10.
The most common weakness is Cross-Site Scripting, behind 2 of the records (100%).
Every one of the 2 issues recorded for GamiPress – Button has a vendor fix available, so running the current release closes all known holes.
All of these findings were reported by Francesco Carlucci. GamiPress – Button is installed on roughly 800 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.9.7.
CVE-2024-2460GamiPress – Button <= 1.0.7 - Authenticated(Contributor+) Stored Cross-Site Scripting via Shortcode
Read the full analysisVulnerability Records

GamiPress – Button
Author
Ruben Garcia
GamiPress – Button let’s you add activity triggers filtered by button clicks adding new activity events on GamiPress! Note: This add-on is designed to award users for button clicks, if you want to award them for link clicks, then you should check the GamiPress – Link add-on. New Events Click any button: When a user clicks on any button. Click a button with a specific ID: When a user clicks on any button with a specific identifier (button id attribute). Click a button with a specific Class: When a user clicks on any button with a specific class (button class attribute). Get a click on any button: When the post/comment author gets clicks on any button. Get a click on a button with a specific ID: When the post/comment author gets clicks on any button with a specific identifier (button id attribute). Get a click on a button with a specific Class: When the post/comment author gets clicks on any button with a specific class (button class attribute). Important: The unique buttons that trigger this activities are the buttons generated by [gamipress_button] shortcode.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C