Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in tagDiv tagDiv Opt-In Builder td-subscription allows Blind SQL Injection.This issue affects tagDiv Opt-In Builder: from n/a through 1.7.6.
Published: 2026-10-09
Score: 9.3 Critical
EPSS: n/a
KEV: No
Impact: SQL Injection leading to data extraction
Action: Immediate Patch
AI Analysis

Impact

The vulnerability in the tagDiv Opt‑In Builder WordPress plugin allows a blind SQL injection that can be used to extract sensitive database information, potentially compromising the entire site. The flaw stems from unsanitized input that is incorporated directly into SQL commands, a classic SQL injection weakness categorized as CWE‑89. Because the injection is blind, an attacker can infer data from the response timing and errors rather than receiving it directly, but the impact remains severe as it enables full database compromise once the attacker gathers enough information.

Affected Systems

All installations of the tagDiv Opt‑In Builder plugin version 1.7.6 or earlier are affected. The plugin is distributed by tagDiv and commonly integrated into WordPress sites. No specific WordPress core or theme versions are listed as directly affecting the issue, but any site using this plugin and containing the vulnerable code is at risk.

Risk and Exploitability

The CVSS score of 9.3 indicates critical severity, and while the EPSS score is not available, the absence of a listed KEV status suggests exploitation has not yet been reported in the wild. Attackers can potentially trigger the injection via the plugin’s public interface, so it is likely an unauthenticated or low‑privilege vector. The lack of observable mitigation in the hosted environment means that a site operator should treat this as an imminent threat and prioritize remediation.

Generated by OpenCVE AI on October 9, 2026 at 12:07 UTC.

Remediation

Vendor Solution

Update the WordPress tagDiv Opt-In Builder plugin to the latest available version (at least 1.7.7).


OpenCVE Recommended Actions

  • Update the tagDiv Opt‑In Builder plugin to version 1.7.7 or later.
  • If the plugin is not required, remove or deactivate it to eliminate the attack surface.
  • Restrict access to the plugin’s public endpoint by implementing network rules or disabling unauthenticated requests until a patch is applied.

Generated by OpenCVE AI on October 9, 2026 at 12:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 09 Oct 2026 10:15:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in tagDiv tagDiv Opt-In Builder td-subscription allows Blind SQL Injection.This issue affects tagDiv Opt-In Builder: from n/a through 1.7.6.
Title WordPress tagDiv Opt-In Builder plugin <= 1.7.6 - SQL Injection vulnerability
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 9.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-10-09T10:00:20.965Z

Reserved: 2026-09-23T00:18:19.472Z

Link: CVE-2026-96330

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-09T10:16:43.917

Modified: 2026-10-09T13:20:48.273

Link: CVE-2026-96330

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-09T12:15:05Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')