CVE-2026-77764: Unknown Gamipress

Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.

The GamiPress WordPress plugin before 7.9.9.6 does not properly restrict its video watch-tracking functionality, allowing users with a role as low as Subscriber to award the configured gamification points, achievements and ranks to arbitrary users including administrators, and to accrue them without limit.

Affected products

  • Unknown Gamipress: before 7.9.9.6 (fixed in 7.9.9.6)

Published 2026-09-02. Last modified 2026-09-03.