Impact
The plugin accepts user input that is directly incorporated into an SQL query without proper escaping or parameterization, which gives an attacker the ability to inject arbitrary SQL code. When the injection succeeds, the attacker can retrieve sensitive data from the database by performing blind query tests, and can also modify or delete records. This flaw can enable a full compromise of the website’s data and potentially undermine the integrity of the site’s content.
Affected Systems
WordPress installations that utilize the tagDiv Opt-In Builder (td-subscription) plugin version 1.7.6 or earlier are affected. The vulnerability applies to all sites that have not upgraded past this release, regardless of customization or active themes.
Risk and Exploitability
The CVSS score of 8.5 reflects the high impact and potential for remote exploitation. EPSS information is not available, and the vulnerability is currently not listed in the CISA KEV catalog. The likely attack vector is remote, where an unauthenticated actor submits crafted HTTP requests to endpoints handled by the plugin, bypassing authentication and exploiting the lack of input sanitization to send blind SQL queries. Successful exploitation would allow data extraction or modification without the need for verified credentials.
OpenCVE Enrichment