CVE-2023-25715: WordPress GamiPress Plugin <= 2.5.6 is vulnerable to Broken Access Control
Missing Authorization vulnerability in GamiPress GamiPress – The #1 gamification plugin to reward points, achievements, badges & ranks in WordPress.This issue affects GamiPress – The #1 gamification plugin to reward points, achievements, badges & ranks in WordPress: from n/a through 2.5.6.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-25715?
CVE-2023-25715 is classified as a critical vulnerability due to its potential for unauthorized manipulation of user points.
How do I fix CVE-2023-25715?
To fix CVE-2023-25715, update the GamiPress plugin to version 2.5.7 or later.
What software is affected by CVE-2023-25715?
CVE-2023-25715 affects GamiPress versions up to and including 2.5.6.
What kind of vulnerability is CVE-2023-25715?
CVE-2023-25715 is a Missing Authorization vulnerability that allows manipulation of user points.
Who should be concerned about CVE-2023-25715?
WordPress site administrators using GamiPress version 2.5.6 or earlier should be concerned about CVE-2023-25715.