ZeroHour

CVE-2026-81287

large

Subscriber SQL Injection in WordPress Charitable Plugin (<= 1.8.12.1)

CVSS 3.1
8.5 high
EPSS
<1%p20
Published
()
Modified
AI analysis

CVE-2026-81287 is an SQL injection flaw (CWE-89) in the Charitable WordPress donation plugin affecting all versions up to and including 1.8.12.1. It is triggered by an authenticated request from a low-privileged account — attacker needs only Subscriber-level privileges, so any WordPress site with open or permitted user registration is reachable from a signed-in attacker. A successful injection can expose database contents, with the CVSS vector indicating a high confidentiality impact and limited availability impact. Any WordPress site running Charitable 1.8.12.1 or earlier is affected. There is no public proof-of-concept, the flaw is not in CISA KEV, and EPSS puts 30-day exploitation probability at roughly 0.3%, so exploitation is currently believed to be minimal or absent.

What to do: Update Charitable to a fixed release as soon as one is available (the data specifies the affected range as <= 1.8.12.1 but not the fixed version, so verify the vendor changelog for the patched release). Until then, restrict or disable Subscriber-level registrations on affected sites and review logs for anomalous database queries from low-privileged user sessions. Monitor for public proof-of-concept disclosures given the high severity rating.

Affected
Charitable (WordPress donation plugin)<= 1.8.12.1
Estimated exposure
large≈20,000+ WordPress sites (plugin active installs in the tens of thousands) — Estimate based on the Charitable donation plugin's published WordPress.org active-install count, which is in the tens of thousands of sites; actual exposed count depends on how many of those sites allow Subscriber-level registrations.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Subscriber SQL Injection in Charitable <= 1.8.12.1 versions.

Ecosystems
WordPress
Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L

In the news

No ingested article mentions this CVE yet.