PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-48874 Ruben Garcia CVE debrief

CVE-2026-48874 is a HIGH severity vulnerability (CVSS Score: 8.5) affecting GamiPress plugin versions up to 7.8.7. The vulnerability allows for Subscriber SQL Injection and has been publicly disclosed on June 15, 2026.

Vendor
Ruben Garcia
Product
GamiPress
CVSS
HIGH 8.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-06-15
Original CVE updated
2026-06-15
Advisory published
2026-06-15
Advisory updated
2026-06-15

Who should care

Users of GamiPress plugin versions up to 7.8.7 should update to a patched version to prevent Subscriber SQL Injection attacks.

Technical summary

The vulnerability is caused by a SQL injection weakness (CWE-89) in the GamiPress plugin. The CVSS vector is CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L.

Defensive priority

HIGH

Recommended defensive actions

  • Update GamiPress plugin to a version greater than 7.8.7.
  • Review and restrict database access for Subscriber roles.

Evidence notes

The CVE record was obtained from the official CVE.org website [cve-org]. Additional details were obtained from the NVD database [nvd].

Sources and references

Verified primary and authoritative sources

  • CVE-2026-48874 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-48874

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-48874 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-48874

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.