The GamiPress WordPress plugin before 6.8.9's access control mechanism fails to properly restrict access to its settings, permitting Authors to manipulate requests and extend access to lower privileged users, like Subscribers, despite initial settings prohibiting such access. This vulnerability resembles broken access control, enabling unauthorized users to modify critical GamiPress WordPress plugin before 6.8.9 configurations.
Metrics
Affected Vendors & Products
References
History
Thu, 08 May 2025 18:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Gamipress
Gamipress gamipress |
|
Weaknesses | NVD-CWE-noinfo | |
CPEs | cpe:2.3:a:gamipress:gamipress:*:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Gamipress
Gamipress gamipress |

Status: PUBLISHED
Assigner: WPScan
Published: 2024-04-29T06:00:01.678Z
Updated: 2024-08-01T19:18:46.478Z
Reserved: 2024-03-15T14:33:02.898Z
Link: CVE-2024-2505

Updated: 2024-08-01T19:18:46.478Z

Status : Analyzed
Published: 2024-04-29T06:15:07.937
Modified: 2025-05-08T18:24:45.817
Link: CVE-2024-2505

No data.