Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ruben Garcia GamiPress gamipress allows SQL Injection.This issue affects GamiPress: from n/a through <= 7.4.5.
Published: 2025-06-06
Score: 7.6 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an SQL injection flaw introduced by improper neutralization of special elements in SQL commands within the GamiPress plugin. It allows an attacker to inject arbitrary SQL statements, potentially reading, modifying or deleting sensitive data stored in the WordPress database. This manifests the weakness identified as CWE‑89 and can be exploited to disrupt confidentiality and integrity of user data.

Affected Systems

The issue impacts WordPress sites running the GamiPress plugin from the earliest release up to and including version 7.4.5. Sites that still use these affected releases are at risk; newer releases are not affected.

Risk and Exploitability

With a CVSS score of 7.6 the vulnerability is considered high severity. The EPSS score is reported as less than 1%, indicating that the likelihood of exploitation is currently low, and it is not listed in the CISA KEV catalog. The likely attack vector is remote, via HTTP requests that the plugin processes. An attacker would need to craft inputs that reach the vulnerable code paths, which are typically exposed through public plugin pages. Provided the WordPress site is reachable over the internet, the exploitation conditions are realistic.

Generated by OpenCVE AI on April 30, 2026 at 18:35 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade GamiPress to version 7.4.6 or later to apply the vendor patch that removes the SQL injection flaw.
  • If an upgrade cannot be performed immediately, disable or remove the GamiPress plugin to eliminate the vulnerable code path.
  • Implement a Web Application Firewall rule to block common SQL injection patterns on the plugin’s endpoints as an additional safeguard.

Generated by OpenCVE AI on April 30, 2026 at 18:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-17246 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ruben Garcia GamiPress allows SQL Injection. This issue affects GamiPress: from n/a through 7.4.5.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ruben Garcia GamiPress allows SQL Injection. This issue affects GamiPress: from n/a through 7.4.5. Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ruben Garcia GamiPress gamipress allows SQL Injection.This issue affects GamiPress: from n/a through <= 7.4.5.
Title WordPress GamiPress <= 7.4.5 - SQL Injection Vulnerability WordPress GamiPress plugin <= 7.4.5 - SQL Injection Vulnerability
References
Metrics cvssV3_1

{'score': 7.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L'}


Fri, 06 Jun 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 06 Jun 2025 13:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ruben Garcia GamiPress allows SQL Injection. This issue affects GamiPress: from n/a through 7.4.5.
Title WordPress GamiPress <= 7.4.5 - SQL Injection Vulnerability
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 7.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:13:01.339Z

Reserved: 2025-06-04T09:42:17.746Z

Link: CVE-2025-49326

cve-icon Vulnrichment

Updated: 2025-06-06T16:10:58.345Z

cve-icon NVD

Status : Deferred

Published: 2025-06-06T13:15:49.323

Modified: 2026-04-23T15:31:28.310

Link: CVE-2025-49326

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T18:45:21Z

Weaknesses