Executive brief
GamiPress is a popular WordPress plugin used to add gamification features like points, badges, and rewards to websites. A security flaw allows unauthenticated attackers to interact directly with the site's database, which could lead to the theft of sensitive customer data or administrative information. This vulnerability is considered high-risk as it can be exploited remotely without any login credentials.
Technical details
A SQL injection vulnerability exists in the GamiPress plugin for WordPress due to improper neutralization of special elements used in SQL commands (CWE-89). The flaw is present in versions up to and including 7.9.7. An unauthenticated remote attacker can exploit this by sending specially crafted network requests to the affected site, allowing them to bypass security controls and directly query the underlying database. This can result in the extraction of sensitive information, such as user credentials or site configuration data. The issue has been addressed in version 7.9.8.
Affected products
- Ruben Garcia GamiPress <= 7.9.7
Timeline
- 2026-06-22: other: Reported by qdtad
- 2026-07-23: advisory: Patchstack advisory published
- 2026-07-27: disclosed: CVE published to NVD
- 2026-07-27: patched: Patch available in version 7.9.8