GamiPress
cpe:2.3:a:gamipress:gamipress:*:*:*:*:wordpress:*:*
- <= 7.9.4
A vulnerability allowing insecure direct object reference has been identified in the GamiPress WordPress plugin, specifically in versions through 7.9.4. The issue arises from a lack of proper validation on the 'access' parameter, which is user-controlled. This vulnerability enables unauthenticated attackers to access private GamiPress activity log entries of any user. The exposed logs include details on badge earnings, points balance changes, and event records from integrated plugins like WooCommerce, LearnDash, and BuddyPress. The exploitation is made easier because the 'gamipress' nonce is available to all front-end users, allowing for straightforward bypassing of authentication requirements.
Exploitation of this vulnerability allows unauthorized users to view private activity logs of any user, including sensitive information such as badge earnings and points balance changes.
To reproduce this vulnerability, send a request to the 'gamipress_get_logs' AJAX endpoint without authentication. Include the 'access' parameter set to 'private' or 'both' and specify a 'user_id' that is not the current user's ID. The response will include private log entries that should not be accessible.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.