GamiPress <= 7.9.7 - Authenticated (Subscriber+) SQL Injection
Strategic Overview
- Status
- Patched in 7.9.8
- Affected Plugin
- GamiPress – Gamification plugin to reward points, badges & ranks in WordPress, now with AI
- Affected Version
<= 7.9.7- CVSS
- 6.5Medium
- Weakness type
- CWE-89 · Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
- CVE
CVE-2026-15439
At a glance
CVE-2026-15439 is a medium-severity Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in the GamiPress WordPress plugin, affecting versions <= 7.9.7. It carries a CVSS score of 6.5 (reachable over the network; low attack complexity; high confidentiality impact). Exploitation requires an authenticated account at Subscriber level or above. The issue is fixed in version 7.9.8; sites on affected versions should update now. Disclosed September 2026, reported by Nox Axter.
Vulnerability Overview
The GamiPress plugin for WordPress is vulnerable to authenticated (Subscriber+) SQL Injection via the 'q' parameter of the wpForo integration AJAX selector (action gamipress_wpforo_get_posts) in versions up to, and including, 7.9.7. The value is passed only through $wpdb->esc_like() and interpolated directly into a single-quoted LIKE clause with no %s placeholder. Because esc_like() runs after WordPress core magic quotes, it doubles the injected backslash (\' -> \\'), which MySQL reads as one literal backslash followed by a live closing quote, allowing the attacker to break out of the string and inject boolean-based SQL. The wpForo plugin only needs to be active to register the callback; no wpForo vulnerability is used. Requires a Subscriber account, which can read the gamipress_admin nonce (exposed on every admin page, e.g. /wp-admin/profile.php). Note: the researcher's Simple:Press vectors (PoC 2 & 3) do not reproduce in current code, which uses $wpdb->prepare() with %s placeholders; only the wpForo selector is confirmed.
Technical Analysis
The vector marks this flaw as remotely reachable over the network, with low attack complexity — no special timing or configuration is needed, and no interaction from a victim user. A successful exploit has high impact on confidentiality.
CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
GamiPress <= 7.9.7 carries this weakness at esc_like(), and reaching it takes an account at Subscriber level or above. SQL injection happens when request data is concatenated into a query instead of being bound as a parameter, letting an attacker change the structure of the statement rather than just its values.
A working injection can read any table the database user can see, which on a WordPress install means user records, password hashes and session or API secrets stored in options. For GamiPress the fix is 7.9.8: builds <= 7.9.7 are affected, anything from 7.9.8 onward is not.
Remediation
Update to version 7.9.8, or a newer patched version
How does WordSec protect against this?
An attacker needs Subscriber access first, so the firewall sees the attempt as traffic from a logged-in account: WordSec's web application firewall inspects request payloads before WordPress loads them. None of that substitutes for the fix: GamiPress 7.9.8 closes this, and updating the plugin is the step that ends it.
- Firewall
- Alerts
External References
Related records
Same weakness class
Other vulnerabilities in GamiPress – Gamification plugin to reward points, badges & ranks in WordPress, now with AI
- 8.8CVE-2025-47508: GamiPress <= 7.3.7 Local File Inclusion
CVE-2025-47508 - 7.3CVE-2024-13499: GamiPress <= 7.2.1 Arbitrary Shortcode Execution
CVE-2024-13499 - 7.3CVE-2024-13495: GamiPress <= 7.2.1 Arbitrary Shortcode Execution
CVE-2024-13495 - 7.3CVE-2024-11036: GamiPress Arbitrary Shortcode Execution
CVE-2024-11036 - 6.5CVE-2026-48874: GamiPress SQL Injection
CVE-2026-48874 - 6.4CVE-2026-16090: GamiPress <= 7.9.9.1 Stored Cross-Site Scripting
CVE-2026-16090 - 6.4CVE-2026-16091: GamiPress <= 7.9.9.1 Stored Cross-Site Scripting
CVE-2026-16091 - 6.4CVE-2026-15730: GamiPress <= 7.9.9.1 Stored Cross-Site Scripting
CVE-2026-15730
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C