Junglewise Threat Intelligence

CVE-2026-24546: Ruben Garcia GamiPress missing authorization in access control

CVE-2026-24546 · Severity: medium · CVSS 5.3 · Published 2026-05-25

Technologies: Ruben Garcia GamiPress. Vendors: GamiPress.

Executive brief

GamiPress is a popular WordPress plugin used to gamify websites by awarding points, badges, and ranks to users. A security flaw in the plugin's access control settings allows unauthorized individuals to bypass intended security levels. This could lead to unauthorized access to certain plugin features or data, potentially undermining the integrity of the site's reward system.

Technical details

A missing authorization vulnerability (CWE-862) exists in the GamiPress plugin for WordPress through version 7.6.3. The flaw allows an unauthenticated attacker to bypass intended access control security levels due to insufficient validation of user permissions within the plugin's logic. By exploiting this, an attacker can potentially access or manipulate features that should be restricted to higher-privileged users. The issue is resolved in version 7.6.4.

Affected products

  • Ruben Garcia GamiPress n/a through 7.6.3

Timeline

  • 2025-12-24: other: Reported by researcher bosz
  • 2026-05-25: patched: Version 7.6.4 released
  • 2026-05-25: advisory: Published by Patchstack and NVD

References

Related threats