CVE-2026-81287: WordPress Charitable plugin <= 1.8.12.1 - SQL Injection vulnerability
Subscriber SQL Injection in Charitable <= 1.8.12.1 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Charitable pluginto a version that resolves this vulnerability.Fixed in 1.8.12.2
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
The vulnerability is exploitable by an authenticated user with Subscriber-level access or higher. It does not require user interaction and can be reached over the network.
What is the potential impact if exploitation succeeds?
Successful exploitation can expose highly sensitive data and may have an impact beyond the vulnerable WordPress security authority. The available scoring information also indicates a low availability impact, while integrity impact is not indicated.
Which installations should be treated as affected?
WordPress sites using the Charitable plugin at version 1.8.12.1 or earlier should be treated as affected based on the provided version range.