PatchSiren cyber security CVE debrief
CVE-2026-77764 GamiPress CVE debrief
The GamiPress WordPress plugin before 7.9.9.6 does not properly restrict its video watch-tracking functionality, allowing users with a role as low as Subscriber to award the configured gamification points, achievements and ranks to arbitrary users including administrators, and to accrue them without limit. This vulnerability could lead to unauthorized access and privilege escalation on WordPress sites using the GamiPress plugin. The issue arises from insufficient access controls on video watch-tracking, enabling low-privileged users to manipulate gamification elements. Administrators should verify the patch status of GamiPress and monitor for suspicious activity related to gamification points and achievements.
- Vendor
- GamiPress
- Product
- GamiPress WordPress plugin
- CVSS
- MEDIUM 4.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-02
- Original CVE updated
- 2026-09-03
- Advisory published
- 2026-09-02
- Advisory updated
- 2026-09-03
Who should care
Administrators of WordPress sites using the GamiPress plugin, security teams monitoring for potential privilege escalation vulnerabilities, and operators responsible for maintaining the integrity of gamification systems.
Technical summary
The GamiPress WordPress plugin before 7.9.9.6 is vulnerable due to its video watch-tracking functionality not being properly restricted. Users with a Subscriber role can award arbitrary users, including administrators, with gamification points, achievements, and ranks without limit. This could lead to unauthorized access and privilege escalation. The vulnerability exists because the plugin does not adequately enforce access controls on its video watch-tracking feature, allowing low-privileged users to manipulate gamification elements. Defenders should verify the patch status of GamiPress and monitor for suspicious activity.
Defensive priority
Medium priority due to potential for privilege escalation and unauthorized access.
Recommended defensive actions
- Verify and apply the latest patch for the GamiPress WordPress plugin (version 7.9.9.6 or later).
- Restrict access to sensitive functionality for users with low privileges.
- Monitor for suspicious activity related to gamification points and achievements.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
Evidence notes
Evidence is based on limited source detail from the NVD and a third-party reference. Further verification is recommended. The GamiPress WordPress plugin before 7.9.9.6 does not properly restrict its video watch-tracking functionality, allowing users with a role as low as Subscriber to award the configured gamification points, achievements and ranks to arbitrary users including administrators, and to accrue them without limit. Defenders should verify the patch status of GamiPress and monitor for suspicious activity.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-77764 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-77764
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-77764 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-77764
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://wpscan.com/vulnerability/c272dadd-9fc9-402f-8712-51d16a271e4b/
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.