Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-77764

CVE-2026-77764: GamiPress WordPress Privilege Escalation

CVE-2026-77764 is a privilege escalation vulnerability in the GamiPress WordPress plugin allowing low-privileged users to manipulate gamification rewards. This article covers technical details, affected versions, and mitigation.

Published:

CVE-2026-77764 Overview

CVE-2026-77764 is a broken access control vulnerability in the GamiPress WordPress plugin before version 7.9.9.6. The plugin fails to properly restrict its video watch-tracking functionality. Authenticated users with a role as low as Subscriber can award configured gamification points, achievements, and ranks to arbitrary users, including administrators. Attackers can also accrue rewards without any limit.

The issue is classified under [CWE-639] (Authorization Bypass Through User-Controlled Key) and affects the integrity of gamification data across affected WordPress sites.

Critical Impact

Any authenticated Subscriber can manipulate gamification state for arbitrary users, undermining the integrity of point, achievement, and rank systems site-wide.

Affected Products

  • GamiPress WordPress plugin versions prior to 7.9.9.6
  • WordPress sites exposing the video watch-tracking feature
  • Sites permitting Subscriber-level registration

Discovery Timeline

  • 2026-09-02 - CVE-2026-77764 published to the National Vulnerability Database (NVD)
  • 2026-09-02 - Last updated in NVD

Technical Details for CVE-2026-77764

Vulnerability Analysis

The GamiPress plugin includes a video watch-tracking feature that records completion events and awards gamification rewards. The endpoint that receives these completion events does not enforce authorization checks tying the request to the authenticated user. It also does not verify that the reward criteria were actually met.

As a result, a Subscriber can submit crafted requests to the tracking endpoint. The requests can specify an arbitrary target user identifier, including that of an administrator. The plugin then awards the configured points, achievements, or ranks to that user. The endpoint also lacks rate limiting or replay protection, allowing repeated submissions to accrue rewards without bound.

This behavior falls under [CWE-639], where authorization is derived from a user-controlled key rather than the authenticated session context. The vulnerability does not permit code execution or direct data disclosure. It does allow integrity manipulation of gamification records and any downstream logic that trusts those records.

Root Cause

The root cause is missing server-side authorization on the video tracking handler. The handler accepts a target user identifier from the request without confirming that identifier matches the authenticated session. Watch-completion state is trusted from the client rather than validated on the server.

Attack Vector

Exploitation requires network access and a valid low-privilege account, such as Subscriber. No user interaction from a victim is needed. The attacker sends crafted requests to the tracking endpoint while authenticated. Refer to the WPScan Vulnerability Report for endpoint specifics.

No verified public exploit code is available at this time. The vulnerability mechanism is described in prose; see the WPScan advisory for reproduction steps.

Detection Methods for CVE-2026-77764

Indicators of Compromise

  • Repeated POST or AJAX requests to GamiPress video tracking endpoints originating from Subscriber-level accounts
  • Unexpected point balances, achievement grants, or rank promotions on administrator or high-privilege accounts
  • GamiPress activity log entries showing awards attributed to users who did not initiate video sessions
  • Bursts of watch-completion events from a single account exceeding realistic viewing rates

Detection Strategies

  • Audit the GamiPress activity table for awards granted to administrator accounts and correlate with authenticated session logs
  • Compare the acting user in web server access logs against the target user parameter submitted to tracking requests
  • Baseline normal watch-tracking request volume per user and alert on statistical outliers

Monitoring Recommendations

  • Enable verbose logging on the WordPress admin-ajax.php and REST API routes used by GamiPress
  • Forward WordPress and web server logs to a centralized analytics platform for correlation and retention
  • Alert on privilege changes, achievement unlocks, or rank promotions affecting administrative users

How to Mitigate CVE-2026-77764

Immediate Actions Required

  • Update the GamiPress plugin to version 7.9.9.6 or later on all WordPress installations
  • Review the GamiPress activity log and revert any fraudulent point, achievement, or rank awards
  • Audit Subscriber and low-privilege accounts created in the exposure window and remove suspicious accounts

Patch Information

The vendor addressed the issue in GamiPress 7.9.9.6. Site administrators should apply the update through the WordPress plugin dashboard or via WP-CLI. See the WPScan Vulnerability Report for advisory details.

Workarounds

  • Disable the GamiPress video watch-tracking module until the patched version is deployed
  • Restrict new user registration or require moderation for Subscriber-level accounts
  • Apply a Web Application Firewall (WAF) rule that blocks tracking requests where the target user identifier differs from the authenticated session user
bash
# Update GamiPress via WP-CLI
wp plugin update gamipress --version=7.9.9.6
wp plugin list --name=gamipress --fields=name,status,version

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.