Sceawere

Vulnerability Detail

CVE-2026-14379UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

GamiPress Stored Cross-Site Scripting

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.4
Creation Date
2h ago
Vendor
rubengc
Product
GamiPress – Gamification plugin to reward points, badges & ranks in WordPress, now with AI
Attack Type
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'video_id' parameter in all versions up to, and including, 7.9.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.4",
  "pubDate": "2026-10-10T06:16:41.603Z",
  "pubdate": "2026-10-10T06:16:41.603Z",
  "executiveSummary": "The GamiPress plugin for WordPress, up to version 7.9.4, contains a stored Cross-Site Scripting (XSS) vulnerability. This security flaw originates from improper input sanitization and output escaping within the 'video_id' parameter.\nThe vulnerability allows authenticated users with at least subscriber-level permissions to inject malicious JavaScript into web pages. When other users, including administrators, view the affected pages, the malicious payload executes within their browser session.\nThe impact of this vulnerability is significant, as it could lead to unauthorized actions performed on behalf of legitimate users, session hijacking, or the redirection of users to malicious external sites. Given the requirement for authentication, the attack vector is restricted to registered users, though this represents a notable risk for WordPress environments that permit public registrations.\nRisk mitigation is essential, as the vulnerability facilitates the compromise of user sessions and potentially administrative accounts depending on who interacts with the injected content.",
  "technicalDetails": "The vulnerability is classified as Stored Cross-Site Scripting (XSS), stemming from the application's failure to adequately sanitize user-supplied input or encode data before rendering it in the browser. Specifically, the 'video_id' parameter processes input without sufficient validation, allowing attackers to submit arbitrary script tags.\nThe attack flow begins when an authenticated attacker, holding a minimum privilege level of subscriber, submits a crafted request containing an XSS payload via the 'video_id' parameter. Because the application stores this input directly in the database without appropriate filtering, the malicious script becomes persistent.\nWhen a legitimate user or administrator navigates to a page where the stored 'video_id' is dynamically rendered, the browser interprets the injected JavaScript as legitimate code. This executes the script within the context of the user's active session. Because the script runs in the user's browser, it gains access to the Document Object Model (DOM) and can perform actions such as extracting session cookies, CSRF tokens, or modifying the page content in real-time.\nThe exploitation process is straightforward: the attacker identifies the endpoint processing the 'video_id' parameter and crafts an HTTP request where the parameter value includes a payload such as <script>alert('XSS')</script>. Upon successful submission, the script is persisted server-side. The vulnerability remains effective across all versions up to and including 7.9.4.\nThe security impact extends beyond simple site defacement. If the script targets an administrator, the attacker could theoretically execute administrative functions, such as creating new malicious user accounts, installing malicious plugins, or altering site configurations. The lack of output encoding acts as the primary failure point, as the browser treats the stored data as executable markup rather than plain text. This is a common flaw in plugins that handle multimedia parameters without robust sanitization libraries or context-aware escaping functions."
}
CVE-2026-14379: GamiPress Stored Cross-Site Scripting (MEDIUM Severity, CVSS: 6.4) | Sceawere