Impact
The vulnerability allows an authenticated user with contributor or greater privileges to store malicious scripts within the ‘gamipress_rank’ shortcode because the plugin does not properly sanitize or escape the content. When an affected page is viewed, the embedded script runs in the context of the site’s users, creating risk of data theft or defacement. This flaw is an instance of CWE‑79.
Affected Systems
The impacted product is the GamiPress gamification plugin for WordPress. All releases up to and including version 7.9.9.1 are vulnerable. The issue resides within the shortcode handling used to display rank information in posts, pages, or custom templates. WordPress environments that have the plugin installed in these versions are therefore at risk.
Risk and Exploitability
The CVSS score of 6.4 classifies the flaw as moderate, and the EPSS score of < 1% indicates a very low probability of exploitation. It is not listed in the CISA KEV catalog. Exploitation requires the attacker to have contributor or higher access to insert the malicious shortcode into a page, post, or template that is subsequently rendered for other users. Because the payload is stored, a single successful insertion can lead to repeated execution on every page view that includes the shortcode.
OpenCVE Enrichment