CVE-2026-15730

GamiPress <= 7.9.9.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'heading_size' Shortcode Attribute

The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'heading_size' Shortcode Attribute in all versions up to, and including, 7.9.9.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The wp_kses_post filter applied at post save does not neutralize this payload because only the inert shortcode text is stored in post_content; the dangerous HTML is synthesized at render time by the shortcode handler, entirely bypassing save-time sanitization.


We have discovered 1,362 live websites that are affected by CVE-2026-15730.

Run a Free Instant Scan




Affected Software

Product  Gamipress
Category Wordpress Plugins
Vulnerable Domains1,362 live websites (100% of Gamipress install base)
Vulnerable Versions
  • from 0 through 7.9.9.1
Vulnerable Versions Count113 versions ( 100% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Jul 28, 2026
  • Updated - Jul 28, 2026

Credits

  • Wordfence PRISM (finder)

Website Distribution by Country

Number of websites using CVE-2026-15730
United States606 websites



Germany136 websites
France59 websites
GB50 websites
Spain36 websites
Cyprus34 websites
Canada32 websites
Italy30 websites
Netherlands27 websites
Brazil26 websites

Website Distribution by TLD

Number of websites using CVE-2026-15730
.com719 websites
.org95 websites
.net47 websites
.de44 websites
.com.br26 websites
.it23 websites
.fr21 websites
.eu19 websites
.nl18 websites
.pl16 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-15730

Top websites that are affected by CVE-2026-15730. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***********.net United States**,***
***************.com United States**,***
***********.com United States***,***
***********.com Spain***,***
*******.com Denmark***,***
********.org France***,***
************************.org GB***,***
*****.org United States***,***
**********.com United States***,***
********.org United States***,***
See full domain list

FAQ

CVE-2026-15730 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Gamipress
A total of 1,362 websites have been identified as vulnerable to CVE-2026-15730, based on global website indexing conducted by WebTechSurvey.
The Gamipress is affected by the CVE-2026-15730 vulnerability.
Gamipress versions up to and including 7.9.9.1 are vulnerable to CVE-2026-15730.