Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 06 Jan 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 06 Jan 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Gamipress
Gamipress gamipress Wordpress Wordpress wordpress |
|
| Vendors & Products |
Gamipress
Gamipress gamipress Wordpress Wordpress wordpress |
Tue, 06 Jan 2026 07:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the gamipress_ajax_get_posts and gamipress_ajax_get_users functions in all versions up to, and including, 7.6.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to enumerate users, including their email addresses and to retrieve titles of private posts. | |
| Title | GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress <= 7.6.1 - Missing Authorization to Authenticated (Subscriber+) Information Exposure | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T17:15:00.410Z
Reserved: 2025-11-30T19:30:05.271Z
Link: CVE-2025-13812
Updated: 2026-01-06T14:32:48.568Z
Status : Deferred
Published: 2026-01-06T08:15:51.707
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-13812
No data.
OpenCVE Enrichment
Updated: 2026-04-21T17:00:12Z