Vulnerability Overview

The GamiPress – The #1 gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is vulnerable to broken access control in all versions up to, and including, 6.8.8. This is due to the plugin not properly restricting specific actions to authorized users. This makes it possible for authentication attackers, with author-level access and above, to to modify the plugins settings.

Technical Analysis

REMEDIATION: Update to version 6.8.9, or a newer patched version --- IDENTIFIER: CWE-284 (Improper Access Control) The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C