GamiPress – Link
GamiPress – Link has one disclosed vulnerability in the WordSec catalog, all reported in 2024; it is fixed as of September 2026. Their average CVSS score is 6.4, and the most serious one scores 6.4 out of 10.
The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).
The one issue recorded for GamiPress – Link has a vendor fix available, so running the current release closes it.
All of these findings were reported by Francesco Carlucci. GamiPress – Link is installed on roughly 700 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.9.7.
CVE-2024-5536GamiPress – Link <= 1.1.4 - Authenticated (Contributor+) Stored Cross-Site Scripting
Read the full analysisVulnerability Records

GamiPress – Link
Author
Ruben Garcia
GamiPress – Link let’s you add activity triggers filtered by link clicks adding new activity events on GamiPress! Note: This add-on is designed to award users for link clicks, if you want to award them for button clicks, then you should check the GamiPress – Button add-on. New Events Click any link: When an user clicks on any link. Click a link with a specific URL: When an user clicks on any link with a specific URL. Click a link with a specific ID: When an user clicks on any link with a specific identifier (link id attribute). Click a link with a specific Class: When an user clicks on any link with a specific class (link class attribute). Get a click on any link: When the post/comment author gets clicks on any link. Get a click on a link with a specific URL: When the post/comment author gets clicks on any link with a specific URL. Get a click on a link with a specific ID: When the post/comment author gets clicks on any link with a specific identifier (link id attribute). Get a click on a link with a specific Class: When the post/comment author gets clicks on any link with a specific class (link class attribute). Important: The unique links that trigger this activities are the links generated by [gamipress_link] shortcode.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C