Impact
The vulnerability in the tagDiv Opt‑In Builder WordPress plugin allows a blind SQL injection that can be used to extract sensitive database information, potentially compromising the entire site. The flaw stems from unsanitized input that is incorporated directly into SQL commands, a classic SQL injection weakness categorized as CWE‑89. Because the injection is blind, an attacker can infer data from the response timing and errors rather than receiving it directly, but the impact remains severe as it enables full database compromise once the attacker gathers enough information.
Affected Systems
All installations of the tagDiv Opt‑In Builder plugin version 1.7.6 or earlier are affected. The plugin is distributed by tagDiv and commonly integrated into WordPress sites. No specific WordPress core or theme versions are listed as directly affecting the issue, but any site using this plugin and containing the vulnerable code is at risk.
Risk and Exploitability
The CVSS score of 9.3 indicates critical severity, and while the EPSS score is not available, the absence of a listed KEV status suggests exploitation has not yet been reported in the wild. Attackers can potentially trigger the injection via the plugin’s public interface, so it is likely an unauthenticated or low‑privilege vector. The lack of observable mitigation in the hosted environment means that a site operator should treat this as an imminent threat and prioritize remediation.
OpenCVE Enrichment