PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-77764 GamiPress CVE debrief

The GamiPress WordPress plugin before 7.9.9.6 does not properly restrict its video watch-tracking functionality, allowing users with a role as low as Subscriber to award the configured gamification points, achievements and ranks to arbitrary users including administrators, and to accrue them without limit. This vulnerability could lead to unauthorized access and privilege escalation on WordPress sites using the GamiPress plugin. The issue arises from insufficient access controls on video watch-tracking, enabling low-privileged users to manipulate gamification elements. Administrators should verify the patch status of GamiPress and monitor for suspicious activity related to gamification points and achievements.

Vendor
GamiPress
Product
GamiPress WordPress plugin
CVSS
MEDIUM 4.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-02
Original CVE updated
2026-09-03
Advisory published
2026-09-02
Advisory updated
2026-09-03

Who should care

Administrators of WordPress sites using the GamiPress plugin, security teams monitoring for potential privilege escalation vulnerabilities, and operators responsible for maintaining the integrity of gamification systems.

Technical summary

The GamiPress WordPress plugin before 7.9.9.6 is vulnerable due to its video watch-tracking functionality not being properly restricted. Users with a Subscriber role can award arbitrary users, including administrators, with gamification points, achievements, and ranks without limit. This could lead to unauthorized access and privilege escalation. The vulnerability exists because the plugin does not adequately enforce access controls on its video watch-tracking feature, allowing low-privileged users to manipulate gamification elements. Defenders should verify the patch status of GamiPress and monitor for suspicious activity.

Defensive priority

Medium priority due to potential for privilege escalation and unauthorized access.

Recommended defensive actions

  • Verify and apply the latest patch for the GamiPress WordPress plugin (version 7.9.9.6 or later).
  • Restrict access to sensitive functionality for users with low privileges.
  • Monitor for suspicious activity related to gamification points and achievements.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.

Evidence notes

Evidence is based on limited source detail from the NVD and a third-party reference. Further verification is recommended. The GamiPress WordPress plugin before 7.9.9.6 does not properly restrict its video watch-tracking functionality, allowing users with a role as low as Subscriber to award the configured gamification points, achievements and ranks to arbitrary users including administrators, and to accrue them without limit. Defenders should verify the patch status of GamiPress and monitor for suspicious activity.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-77764 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-77764

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-77764 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-77764

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.