CVE-2026-24546: WordPress GamiPress plugin <= 7.6.3 - Broken Access Control vulnerability
Published May 25, 2026
·Updated
Missing Authorization vulnerability in Ruben Garcia GamiPress allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects GamiPress: from n/a through 7.6.3.
Affected Software
1 affected component
wordpress/gamipress<=7.6.3
Remediation
Information
Update the WordPress GamiPress Plugin to the latest available version (at least 7.6.4).
Event History
May 25, 2026
CVE Published
via MITRE·07:26 PM
Data Sourced
via MITRE·07:26 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-24546?
CVE-2026-24546 has a medium severity rating of 5.3.
2
What vulnerability is identified by CVE-2026-24546?
CVE-2026-24546 identifies a Broken Access Control vulnerability in the GamiPress WordPress plugin.
3
How do I fix CVE-2026-24546?
To fix CVE-2026-24546, update the WordPress GamiPress Plugin to at least version 7.6.4.
4
Who is affected by CVE-2026-24546?
CVE-2026-24546 affects all versions of GamiPress from n/a through 7.6.3.
5
What kind of issue does CVE-2026-24546 represent?
CVE-2026-24546 represents a missing authorization vulnerability that allows for incorrectly configured access control levels.