CVE-2026-16090: GamiPress <= 7.9.9.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via gamipress_achievement Shortcode
The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'headingsize' Shortcode Attribute in 'gamipressachievement' in all versions up to, and including, 7.9.9.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. WordPress save-time wpksespost does not neutralize this payload because the injected value is stored inside a shortcode attribute rather than as a raw HTML tag, and is only emitted into HTML at render time without escaping.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-16090?
CVE-2026-16090 has a medium severity rating of 6.4.
How do I fix CVE-2026-16090?
To fix CVE-2026-16090, update the GamiPress plugin to version 7.9.9.2 or later.
What type of vulnerability is CVE-2026-16090?
CVE-2026-16090 is categorized as a Stored Cross-Site Scripting (XSS) vulnerability.
Which versions of GamiPress are affected by CVE-2026-16090?
CVE-2026-16090 affects all versions of GamiPress up to and including 7.9.9.1.
Who is affected by CVE-2026-16090?
Users with authenticated Contributor+ roles using affected versions of GamiPress are vulnerable to CVE-2026-16090.