CVE-2026-94177: WordPress GamiPress plugin <= 8.0.2 - SQL Injection vulnerability
Published Sep 30, 2026
·Updated
Unauthenticated SQL Injection in GamiPress <= 8.0.2 versions.
Affected Software
1 affected component
GamiPress GamiPress<=8.0.2
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress GamiPress pluginto a version that resolves this vulnerability.Fixed in 8.0.3
Event History
Sep 30, 2026
CVE Published
via MITRE·12:27 PM
Data Sourced
via MITRE·12:27 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·01:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Does exploitation require an authenticated account?
The provided data is inconsistent: the description calls the issue unauthenticated, while the CVSS vector specifies low privileges required (PR:L). Treat the authentication requirement as unconfirmed until it is verified against the vendor advisory or testing.
2
What impact is indicated by the severity vector?
The CVSS vector indicates high confidentiality impact, no integrity impact, and low availability impact. It also indicates a changed scope (S:C), meaning the vulnerable component may affect another security authority.