Description
Subscriber SQL Injection in Charitable <= 1.8.12.1 versions.
Published: 2026-08-31
Score: 8.5 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Subscriber SQL Injection exists in Charitable plugin versions 1.8.12.1 and earlier. The flaw allows an attacker to inject arbitrary SQL through the subscriber input, giving the attacker the ability to read, modify, or delete data stored by the WordPress site.

Affected Systems

The affected product is the Charitable WordPress plugin developed by Syed Balkhi. Versions up to and including 1.8.12.1 are affected. A WordPress site that has installed one of these vulnerable plugin releases is at risk.

Risk and Exploitability

The CVSS score of 8.5 indicates a high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. The flaw appears in the subscriber endpoint of the plugin; authentication requirements are not specified in the description, so the exact attack prerequisites remain unknown but the vulnerability is exploitable via the affected endpoint.

Generated by OpenCVE AI on August 31, 2026 at 21:56 UTC.

Remediation

Vendor Solution

Update the WordPress Charitable Plugin to the latest available version (at least 1.8.12.2).


OpenCVE Recommended Actions

  • Update the WordPress Charitable Plugin to version 1.8.12.2 or newer.
  • Review any custom subscriber code to ensure that all database interactions use parameterized queries and proper input validation.
  • Disable the subscriber functionality or remove the plugin entirely until the patch is applied, and verify that no other vulnerable WordPress plugins remain installed.

Generated by OpenCVE AI on August 31, 2026 at 21:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 31 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Syed Balkhi
Syed Balkhi charitable
Wordpress
Wordpress wordpress
Vendors & Products Syed Balkhi
Syed Balkhi charitable
Wordpress
Wordpress wordpress

Mon, 31 Aug 2026 20:45:00 +0000

Type Values Removed Values Added
Description Subscriber SQL Injection in Charitable <= 1.8.12.1 versions.
Title WordPress Charitable plugin <= 1.8.12.1 - SQL Injection vulnerability
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 8.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L'}


Subscriptions

Syed Balkhi Charitable
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-31T20:30:42.386Z

Reserved: 2026-08-26T17:33:24.197Z

Link: CVE-2026-81287

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-31T21:17:49.803

Modified: 2026-08-31T21:17:49.803

Link: CVE-2026-81287

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-31T22:00:06Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')