tagDiv Newspaper
cpe:2.3:a:tagdiv:newspaper:*:*:*:*:wordpress:*:*
- <= 1.7
A time-based SQL injection vulnerability has been identified in the tagDiv Opt-In Builder plugin for WordPress, affecting all versions through 1.7. The vulnerability arises from inadequate escaping of user-supplied data in the 'subscriptionCouponId' parameter, allowing authenticated attackers with Subscriber-level access or higher to inject additional SQL queries. This exploitation could lead to unauthorized access to sensitive database information.
Exploitation of this vulnerability allows for time-based SQL injection, where an attacker can manipulate SQL queries to extract sensitive information from the database.
Users are advised to update the tagDiv Opt-In Builder plugin to version 1.7.1 or a newer patched version.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.