Impact
The plugin’s subscriptionCouponId parameter is insufficiently escaped, allowing authenticated users with Subscriber-level access and higher to inject malicious SQL. This flaw is a classic SQL injection (CWE-89) that can discover sensitive data from the database.
Affected Systems
WordPress sites that use TagDiv Opt‑In Builder version 1.7 or earlier, installed from TagDiv, are affected. All preceding releases up to the 1.7 release date are vulnerable.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, while the EPSS score of less than 1% shows low likelihood of exploitation. The vulnerability is not listed in CISA KEV, suggesting it is not actively exploited in the wild. Based on the description, attackers must possess authenticated subscriber or higher privileges, and the time‑based injection would likely require crafting a payload and observing delays to confirm success. An attacker could gain read‑only access to database tables via this vector.
OpenCVE Enrichment
EUVD