What the vulnerability does
01Description
Subscriber SQL Injection in GamiPress <= 7.8.7 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L
What the vulnerability does
Subscriber SQL Injection in GamiPress <= 7.8.7 versions.
Explanation of Vulnerability in Simple Terms
GamiPress versions up to 7.8.7 contain a SQL injection vulnerability in database query handling. An attacker with low-level user privileges can inject malicious SQL code to read sensitive data from the site database, including user information and configuration details. The vulnerability affects the entire site scope and may also cause service disruption.
What an attacker can do
Read sensitive data from the site database, including user records and site configuration.
Potential impact on your site
Unauthorized access to user data, passwords, and site configuration; potential service disruption.
Conditions required to exploit
Attacker must have a low-privilege user account (subscriber, contributor, or similar) on the site.
Key dates
External resources
Related vulnerabilities