Stored Cross-Site Scripting Vulnerability in GamiPress Plugin for WordPress
CVE-2026-14379
6.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 10 October 2026
What is CVE-2026-14379?
The GamiPress plugin for WordPress has a vulnerability that allows authenticated attackers with subscriber-level access or higher to exploit the 'video_id' parameter. This occurs due to inadequate input sanitization and output escaping, enabling the injection of malicious web scripts. If a user accesses a crafted page containing these scripts, it can lead to unauthorized actions and potentially compromise user data, making remediation essential for site security.
Affected Version(s)
GamiPress β Gamification plugin to reward points, badges & ranks in WordPress, now with AI 0 <= 7.9.4