Impact
Subscriber SQL Injection exists in Charitable plugin versions 1.8.12.1 and earlier. The flaw allows an attacker to inject arbitrary SQL through the subscriber input, giving the attacker the ability to read, modify, or delete data stored by the WordPress site.
Affected Systems
The affected product is the Charitable WordPress plugin developed by Syed Balkhi. Versions up to and including 1.8.12.1 are affected. A WordPress site that has installed one of these vulnerable plugin releases is at risk.
Risk and Exploitability
The CVSS score of 8.5 indicates a high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. The flaw appears in the subscriber endpoint of the plugin; authentication requirements are not specified in the description, so the exact attack prerequisites remain unknown but the vulnerability is exploitable via the affected endpoint.
OpenCVE Enrichment