Description
Unauthenticated SQL Injection in GamiPress <= 7.9.7 versions.
Published: 2026-07-27
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an unauthenticated SQL Injection that allows an attacker to inject arbitrary SQL statements through input fields provided by the GamiPress plugin. An attacker can read, modify, or delete sensitive data in the WordPress database, potentially exposing user credentials, site content, or compromising the entire site. The weakness is identified as CWE-89.

Affected Systems

WordPress sites running the GamiPress plugin version 7.9.7 or earlier are affected. This includes any deployment that has not upgraded to version 7.9.8 or later.

Risk and Exploitability

The CVSS score of 9.3 classifies this issue as critical. The EPSS score of 0.00236 indicates a very low probability of exploitation, and it is not listed in the CISA KEV catalog, but the inherent risk remains high. An attacker can exploit this vulnerability without authentication; the likely attack vector is via standard web requests that target vulnerable input parameters of the plugin.

Generated by OpenCVE AI on August 3, 2026 at 17:36 UTC.

Remediation

Vendor Solution

Update the WordPress GamiPress Plugin to the latest available version (at least 7.9.8).


OpenCVE Recommended Actions

  • Update the GamiPress plugin to version 7.9.8 or later.
  • If a patch cannot be applied immediately, restrict access to the GamiPress features so only trusted users can use them, reducing the attack surface.
  • Monitor database and web server logs for abnormal SQL activity and review user accounts for unauthorized changes.

Generated by OpenCVE AI on August 3, 2026 at 17:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 27 Jul 2026 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Ruben Garcia
Ruben Garcia gamipress
Wordpress
Wordpress wordpress
Vendors & Products Ruben Garcia
Ruben Garcia gamipress
Wordpress
Wordpress wordpress

Mon, 27 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Description Unauthenticated SQL Injection in GamiPress <= 7.9.7 versions.
Title WordPress GamiPress plugin <= 7.9.7 - SQL Injection vulnerability
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 9.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L'}


Subscriptions

Ruben Garcia Gamipress
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-27T16:36:29.284Z

Reserved: 2026-07-05T21:27:50.222Z

Link: CVE-2026-59538

cve-icon Vulnrichment

Updated: 2026-07-27T16:36:20.422Z

cve-icon NVD

Status : Deferred

Published: 2026-07-27T15:17:04.460

Modified: 2026-07-27T17:46:02.447

Link: CVE-2026-59538

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T17:45:03Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')