Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in tagDiv tagDiv Opt-In Builder td-subscription allows Blind SQL Injection.This issue affects tagDiv Opt-In Builder: from n/a through 1.7.6.
Published: 2026-10-09
Score: 8.5 High
EPSS: n/a
KEV: No
Impact: Data Exfiltration
Action: Immediate Patch
AI Analysis

Impact

The plugin accepts user input that is directly incorporated into an SQL query without proper escaping or parameterization, which gives an attacker the ability to inject arbitrary SQL code. When the injection succeeds, the attacker can retrieve sensitive data from the database by performing blind query tests, and can also modify or delete records. This flaw can enable a full compromise of the website’s data and potentially undermine the integrity of the site’s content.

Affected Systems

WordPress installations that utilize the tagDiv Opt-In Builder (td-subscription) plugin version 1.7.6 or earlier are affected. The vulnerability applies to all sites that have not upgraded past this release, regardless of customization or active themes.

Risk and Exploitability

The CVSS score of 8.5 reflects the high impact and potential for remote exploitation. EPSS information is not available, and the vulnerability is currently not listed in the CISA KEV catalog. The likely attack vector is remote, where an unauthenticated actor submits crafted HTTP requests to endpoints handled by the plugin, bypassing authentication and exploiting the lack of input sanitization to send blind SQL queries. Successful exploitation would allow data extraction or modification without the need for verified credentials.

Generated by OpenCVE AI on October 9, 2026 at 11:44 UTC.

Remediation

Vendor Solution

Update the WordPress tagDiv Opt-In Builder plugin to the latest available version (at least 1.7.7).


OpenCVE Recommended Actions

  • Update the tagDiv Opt-In Builder plugin to version 1.7.7 or later, which removes the vulnerable code path.
  • If an immediate update is not possible, deactivate or uninstall the plugin to eliminate the entry point for injection.
  • Apply strict input validation or whitelist filtering on any custom endpoints that still rely on the plugin logic, and review database queries for parameterization.

Generated by OpenCVE AI on October 9, 2026 at 11:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 09 Oct 2026 10:15:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in tagDiv tagDiv Opt-In Builder td-subscription allows Blind SQL Injection.This issue affects tagDiv Opt-In Builder: from n/a through 1.7.6.
Title WordPress tagDiv Opt-In Builder plugin <= 1.7.6 - SQL Injection vulnerability
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 8.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-10-09T10:00:20.895Z

Reserved: 2026-09-23T00:18:19.472Z

Link: CVE-2026-96329

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-09T10:16:43.740

Modified: 2026-10-09T13:20:48.273

Link: CVE-2026-96329

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-09T11:45:04Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')