Impact
An unauthenticated SQL Injection flaw exists in WordPress GamiPress plugin versions 8.0.2 and earlier. The vulnerability allows an attacker to inject arbitrary SQL statements through plugin input fields that are not properly sanitized, which can be used to read, modify, or delete database contents. This weakness maps to the common vulnerability class CWE-89.
Affected Systems
The affected product is the WordPress GamiPress plugin developed by Ruben Garcia. Version numbers up to and including 8.0.2 are vulnerable; any installation using these versions of the plugin or earlier is at risk.
Risk and Exploitability
The CVSS score of 8.5 indicates a high severity impact. EPSS data is unavailable and the issue is not listed in the CISA KEV catalog, suggesting that while the vulnerability is serious, widespread exploitation may not yet be reported. Because the flaw is unauthenticated, an attacker only needs to send a crafted request to the plugin’s endpoints from any network location, making exploitation technically straightforward once the correct input vectors are identified.
OpenCVE Enrichment