Impact
The GamiPress WordPress plugin version 7.9.7 and earlier is vulnerable to an authenticated SQL injection through the wpForo integration AJAX selector. An attacker with a Subscriber or higher role can supply a crafted value for the 'q' parameter, which is only sanitized with $wpdb->esc_like() and inserted into a single‑quoted LIKE clause without a proper placeholder. The sanitization process incorrectly doubles backslashes, allowing the injected backslash to escape the closing quote and inject boolean‑based SQL conditions, potentially exposing or manipulating the database contents.
Affected Systems
Any WordPress installation running GamiPress 7.9.7 or older and the wplevel role available. The vulnerability is active only when both plugins are installed and wpForo registers the AJAX callback; no breakpoint exists if wpForo is inactive.
Risk and Exploitability
The CVSS score of 6.5 indicates medium severity. EPSS is not available, but the requirement of only an authenticated user greatly narrows the attack surface, while the exposed gamipress_admin nonce on common admin pages makes the attack feasible for non‑malicious insiders or compromised accounts. The vulnerability is not listed in CISA KEV, yet the potential for data exfiltration and use of the SQL injection for privilege escalation warrants timely remediation.
OpenCVE Enrichment