Input validation vulnerability in GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress 7.4.5

The GamiPress plugin for WordPress has a security issue called SQL Injection. This affects versions up to 7.4.5. The problem is that the plugin does not properly protect user input and does not adequately prepare existing SQL queries. As a result, attackers who are logged in as administrators or above can add their own malicious code to existing queries and potentially access sensitive data from the website’s database.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.