tagDiv Opt-In Builder WordPress Plugin SQL Injection Vulnerability

Vulnerability

A time-based SQL injection vulnerability has been identified in the tagDiv Opt-In Builder plugin for WordPress, affecting all versions through 1.7. The vulnerability arises from inadequate escaping of user-supplied data in the 'subscriptionCouponId' parameter, allowing authenticated attackers with Subscriber-level access or higher to inject additional SQL queries. This exploitation could lead to unauthorized access to sensitive database information.

Impact

Exploitation of this vulnerability allows for time-based SQL injection, where an attacker can manipulate SQL queries to extract sensitive information from the database.

Remediation

Users are advised to update the tagDiv Opt-In Builder plugin to version 1.7.1 or a newer patched version.

Added: Sep 1, 2025, 7:22 PM
Updated: Sep 1, 2025, 7:22 PM

Vulnerability Rating

Custom Algorithm
spread
6.4
impact
2.5
exploitability
5.4
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.