Executive brief
GamiPress is a popular WordPress plugin that adds gamification features (points, badges, leaderboards) to WordPress sites. An authenticated attacker with a Subscriber account can exploit a SQL injection flaw in the wpForo integration to read or modify database contents, potentially exposing sensitive site data or user information. The vulnerability requires only basic site access and can be exploited using publicly visible nonces.
Technical details
The vulnerability is a boolean-based SQL injection in the 'q' parameter of the gamipress_wpforo_get_posts AJAX action. The vulnerable code passes user input through $wpdb->esc_like() but then directly interpolates it into a single-quoted LIKE clause without using $wpdb->prepare() with %s placeholders. Because esc_like() doubles backslashes after WordPress magic quotes, an attacker can inject a backslash-quote sequence that MySQL interprets as a literal backslash followed by a closing quote, breaking out of the LIKE clause. The attack requires an authenticated Subscriber account (the lowest user role) and a valid gamipress_admin nonce that is exposed on all WordPress admin pages. The wpForo plugin must be active to register the vulnerable AJAX callback, but no wpForo-specific vulnerability is exploited. Patches should use proper parameterized queries with $wpdb->prepare().
Affected products
- GamiPress GamiPress up to and including 7.9.7
Timeline
- 2026-09-11: disclosed