GamiPress <= 6.8.8 - Broken Access Control
2024-04-08 00:00
cyc707Strategic Overview
StatusPatched in 6.8.9
Affected PluginGamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress
Affected Version
<= 6.8.8CVSS4.3Medium
CVE
CVE-2024-2505Vulnerability Overview
The GamiPress – The #1 gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is vulnerable to broken access control in all versions up to, and including, 6.8.8. This is due to the plugin not properly restricting specific actions to authorized users. This makes it possible for authentication attackers, with author-level access and above, to to modify the plugins settings.
Technical Analysis
REMEDIATION: Update to version 6.8.9, or a newer patched version --- IDENTIFIER: CWE-284 (Improper Access Control) The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C