Executive brief
GamiPress is a popular WordPress plugin used to add gamification features like points, badges, and rewards to websites. A security flaw allows users with basic 'Subscriber' accounts to perform unauthorized database queries. This could lead to the theft of sensitive customer data, exposure of site configuration details, or disruption of website operations.
Technical details
A SQL injection vulnerability exists in the GamiPress plugin for WordPress due to improper neutralization of special elements in SQL commands (CWE-89). The flaw is accessible to authenticated users with at least 'Subscriber' level privileges. By sending specially crafted requests, a remote attacker can bypass intended query logic to extract sensitive information from the WordPress database or cause minor service disruptions. The vulnerability is mitigated in version 7.8.8. The CVSS 3.1 score of 8.5 reflects a high impact on confidentiality due to the potential for full database readout.
Affected products
- GamiPress GamiPress <= 7.8.7
Timeline
- 2026-04-28: other: Reported by researcher kai63001
- 2026-06-02: patched: Patch released in version 7.8.8
- 2026-06-15: advisory: NVD and Patchstack advisories published