Impact
The vulnerability arises because the GamiPress plugin does not enforce proper restrictions on its video watch‑tracking feature. As a result, users with a Subscriber role can trigger the awarding of configured points, achievements, and ranks to any chosen user. An attacker could therefore inflate the reputations of privileged accounts, give administrators unwarranted rewards, and accumulate points indefinitely, undermining the integrity of the gamification system.
Affected Systems
All installations of the GamiPress WordPress plugin with a version number lower than 7.9.9.6 are affected. The flaw applies to default role configurations and affects any site that has the video watch‑tracking feature enabled.
Risk and Exploitability
The lack of proper authorization control presents a moderate risk scenario. Because the flaw can be triggered entirely from a normal user interface, remote attackers can exploit it without requiring elevated permissions. The CVSS score is 4.3, indicating a moderate threat. The EPSS score is not available and the issue is not listed in the CISA KEV catalog, so current exploit activity is unknown. Nonetheless, the potential impact justifies priority remediation.
OpenCVE Enrichment