Impact
The GamiPress plugin contains an insecure direct object reference (CWE-639) that exposes private activity logs via the 'access' parameter. The 'gamipress' nonce is broadcast to all front‑end users, making the authentication barrier trivially bypassable. An unauthenticated attacker can view sensitive data such as badge earnings, point balances, and event records, thereby compromising the confidentiality of all users on the site.
Affected Systems
The flaw affects all WordPress sites running any GamiPress version up to and including 7.9.4. The vendor is rubengc, and the plugin is commonly used to reward points, achievements, badges, and ranks.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity, and the EPSS score of <1% suggests low likelihood of exploitation at this time. However, because no authentication is required and the nonce is easily accessible on every front‑end page, the attack surface remains wide. The vulnerability is not currently listed in the CISA KEV catalog.
OpenCVE Enrichment