rubengc Vulnerabilities and Affected Products
Vulnerabilities associated with GamiPress – Button.
Products
Clear product- GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress11 vulnerabilities
- AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress4 vulnerabilities
- GamiPress – Button1 vulnerability
- GamiPress – Link1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2024-2460MEDIUM | GamiPress – Button <= 1.0.7 - Authenticated(Contributor+) Stored Cross-Site Scripting via ShortcodeThe GamiPress – Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'gamipress_button' shortcode in all versions up to, and including, 1.0.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CWE-79Mar 20, 2024 | CVSS6.4v3.1 | EPSS0.435% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |