PatchSiren

rubengc CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM rubengc CVE published 2026-09-11

CVE-2026-15439

The GamiPress plugin for WordPress, up to and including version 7.9.7, is vulnerable to authenticated SQL Injection via the 'q' parameter of the wpForo integration AJAX selector (action gamipress_wpforo_get_posts). An attacker with a Subscriber account can exploit this by injecting boolean-based SQL, breaking out of the string and injecting SQL, due to the value being passed through $wpdb->esc_like() and [truncated]

MEDIUM rubengc CVE published 2026-08-01

CVE-2026-16091

The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'gamipress_rank' Shortcode in all versions up to, and including, 7.9.9.1 due to insufficient input sanitization and output escaping. This vulnerability allows authenticated attackers with contributor-level access to inject web scripts tha [truncated]

MEDIUM rubengc CVE published 2026-08-01

CVE-2026-16090

The GamiPress plugin for WordPress, specifically versions up to and including 7.9.9.1, is vulnerable to Stored Cross-Site Scripting (XSS) via the 'heading_size' Shortcode Attribute in 'gamipress_achievement'. This vulnerability is due to insufficient input sanitization and output escaping, allowing authenticated attackers with contributor-level access and above to inject arbitrary web scripts. These scrip [truncated]