CVE-2026-77764: Unknown Gamipress
Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.
The GamiPress WordPress plugin before 7.9.9.6 does not properly restrict its video watch-tracking functionality, allowing users with a role as low as Subscriber to award the configured gamification points, achievements and ranks to arbitrary users including administrators, and to accrue them without limit.
Affected products
- Unknown Gamipress: before 7.9.9.6 (fixed in 7.9.9.6)
Published 2026-09-02. Last modified 2026-09-03.