CVE-2023-25715 MEDIUM

CVE-2023-25715: WordPress GamiPress Plugin <= 2.5.6 is vulnerable to Broken Access Control

Vendor Gamipress
Product GamiPress – The #1 gamification plugin to reward points, achievements, badges & ranks in WordPress
Weakness CWE-862 · Missing authorization
Published December 19, 2023
Last update April 28, 2026

CVSS base score

5.4/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality None
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L

What the vulnerability does

01Description

Missing Authorization vulnerability in GamiPress GamiPress – The #1 gamification plugin to reward points, achievements, badges & ranks in WordPress.This issue affects GamiPress – The #1 gamification plugin to reward points, achievements, badges & ranks in WordPress: from n/a through 2.5.6.

Explanation of Vulnerability in Simple Terms

02Summary

GamiPress fails to properly check user permissions before allowing certain actions. A logged-in user with low privileges can modify site data or disrupt service without authorization. The vulnerability affects versions up to 2.5.6. Update to a version newer than 2.5.6 to resolve this issue.

What an attacker can do

03Attacker Capabilities

A logged-in user can modify site data or cause service disruption without proper authorization.

Potential impact on your site

04Site Impact

Unauthorized users can alter gamification data, points, or badges, compromising the integrity of your reward system.

Conditions required to exploit

05Prerequisites

Attacker must have a low-privilege user account on the WordPress site.

Key dates

06Disclosure timeline

December 19, 2023 CVE published
April 28, 2026 Record updated

Related vulnerabilities

08Related CVE