CVE-2026-81287
largeSubscriber SQL Injection in WordPress Charitable Plugin (<= 1.8.12.1)
CVE-2026-81287 is an SQL injection flaw (CWE-89) in the Charitable WordPress donation plugin affecting all versions up to and including 1.8.12.1. It is triggered by an authenticated request from a low-privileged account — attacker needs only Subscriber-level privileges, so any WordPress site with open or permitted user registration is reachable from a signed-in attacker. A successful injection can expose database contents, with the CVSS vector indicating a high confidentiality impact and limited availability impact. Any WordPress site running Charitable 1.8.12.1 or earlier is affected. There is no public proof-of-concept, the flaw is not in CISA KEV, and EPSS puts 30-day exploitation probability at roughly 0.3%, so exploitation is currently believed to be minimal or absent.
What to do: Update Charitable to a fixed release as soon as one is available (the data specifies the affected range as <= 1.8.12.1 but not the fixed version, so verify the vendor changelog for the patched release). Until then, restrict or disable Subscriber-level registrations on affected sites and review logs for anomalous database queries from low-privileged user sessions. Monitor for public proof-of-concept disclosures given the high severity rating.
| Charitable (WordPress donation plugin) | <= 1.8.12.1 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Subscriber SQL Injection in Charitable <= 1.8.12.1 versions.
- Ecosystems
- WordPress
- Weakness
- CWE-89
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L
In the news0 stories
No ingested article mentions this CVE yet.