CVE-2026-59538

WordPress GamiPress plugin <= 7.9.7 - SQL Injection vulnerability

Unauthenticated SQL Injection in GamiPress <= 7.9.7 versions.


We have discovered 1,362 live websites that are affected by CVE-2026-59538.

Run a Free Instant Scan




Affected Software

Product  Gamipress
Category Wordpress Plugins
Vulnerable Domains1,362 live websites (100% of Gamipress install base)
Vulnerable Versions
  • from 0 through 7.9.7
Vulnerable Versions Count113 versions ( 100% of all versions)


Common Weakness Enumeration

CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')



Details

  • Published - Jul 27, 2026
  • Updated - Jul 27, 2026

Credits

  • qdtad | Patchstack Bug Bounty Program (finder)

Website Distribution by Country

Number of websites using CVE-2026-59538
United States606 websites



Germany136 websites
France59 websites
GB50 websites
Spain36 websites
Cyprus34 websites
Canada32 websites
Italy30 websites
Netherlands27 websites
Brazil26 websites

Website Distribution by TLD

Number of websites using CVE-2026-59538
.com719 websites
.org95 websites
.net47 websites
.de44 websites
.com.br26 websites
.it23 websites
.fr21 websites
.eu19 websites
.nl18 websites
.pl16 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-59538

Top websites that are affected by CVE-2026-59538. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***********.net United States**,***
***************.com United States**,***
***********.com United States***,***
***********.com Spain***,***
*******.com Denmark***,***
********.org France***,***
************************.org GB***,***
*****.org United States***,***
**********.com United States***,***
********.org United States***,***
See full domain list

FAQ

CVE-2026-59538 is Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in Gamipress
A total of 1,362 websites have been identified as vulnerable to CVE-2026-59538, based on global website indexing conducted by WebTechSurvey.
The Gamipress is affected by the CVE-2026-59538 vulnerability.
Gamipress versions up to and including 7.9.7 are vulnerable to CVE-2026-59538.