Impact
The vulnerability is an unauthenticated SQL Injection that allows an attacker to inject arbitrary SQL statements through input fields provided by the GamiPress plugin. An attacker can read, modify, or delete sensitive data in the WordPress database, potentially exposing user credentials, site content, or compromising the entire site. The weakness is identified as CWE-89.
Affected Systems
WordPress sites running the GamiPress plugin version 7.9.7 or earlier are affected. This includes any deployment that has not upgraded to version 7.9.8 or later.
Risk and Exploitability
The CVSS score of 9.3 classifies this issue as critical. The EPSS score of 0.00236 indicates a very low probability of exploitation, and it is not listed in the CISA KEV catalog, but the inherent risk remains high. An attacker can exploit this vulnerability without authentication; the likely attack vector is via standard web requests that target vulnerable input parameters of the plugin.
OpenCVE Enrichment