Sceawere

Vulnerability Detail

CVE-2026-96330UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

SQL Injection in tagDiv Opt-In

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.3
Creation Date
3h ago
Vendor
tagDiv
Product
tagDiv Opt-In Builder
Attack Type
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L
Attack Complexity
LOW

Narrative and Response

Description

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in tagDiv tagDiv Opt-In Builder td-subscription allows Blind SQL Injection.This issue affects tagDiv Opt-In Builder: from n/a through 1.7.6.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.3",
  "pubDate": "2026-10-09T10:16:43.917Z",
  "pubdate": "2026-10-09T10:16:43.917Z",
  "executiveSummary": "The tagDiv Opt-In Builder plugin for WordPress is affected by a Blind SQL Injection vulnerability, identified as Improper Neutralization of Special Elements used in an SQL Command (CWE-89).\nThis vulnerability exists within versions 1.7.6 and prior, allowing unauthenticated or authenticated attackers to manipulate database queries via unsanitized input vectors.\nThe primary risk involves the unauthorized extraction of sensitive information from the underlying database, such as user credentials, configuration data, or private site content.\nBy leveraging blind exploitation techniques, an attacker can infer database content by observing application responses to time-based or boolean-based SQL queries.\nThis flaw grants an attacker the ability to bypass security controls and interact directly with the database layer, potentially leading to a complete compromise of the site's data integrity.\nSuccessful exploitation requires minimal specialized knowledge and can be automated, making it a critical security risk for site administrators.",
  "technicalDetails": "The root cause of this vulnerability is the failure of the tagDiv Opt-In Builder plugin to properly sanitize and parameterize user-supplied input before incorporating it into SQL queries. The plugin lacks sufficient input validation and prepared statements, allowing for the injection of malicious SQL commands through parameters processed by the plugin.\nAs a Blind SQL Injection vulnerability, the attack does not typically return query results directly in the application's HTTP response. Instead, the attacker must employ boolean-based or time-based inference techniques. In a boolean-based attack, the attacker injects SQL conditions (e.g., 'AND 1=1' or 'AND 1=0') and monitors for differences in the HTTP response body or length to confirm the success of the injected logic.\nIn a time-based attack, the attacker injects database commands such as 'SLEEP()' or heavy procedural calls that cause the server to pause before responding. By observing the duration of the server's response time, the attacker can verify that their injected query was executed successfully, allowing for the character-by-character exfiltration of data from the database management system.\nThe attack flow proceeds as follows: First, the attacker identifies a vulnerable request parameter within the tagDiv Opt-In Builder plugin interface. Second, the attacker crafts a malicious payload containing SQL syntax designed to query the database schema, version, or user tables. Third, the attacker transmits this payload to the affected application. The backend database processes the injected malicious code, and the server's response serves as an oracle to confirm the validity of the attacker's guesses.\nThis vulnerability is particularly severe because it can often be performed without administrative privileges. By exploiting this flaw, an attacker could potentially gain elevated access, modify records, or export the entire database content. Because the vulnerability persists through version 1.7.6, the application remains exposed until proper input neutralization, such as the use of WordPress '$wpdb->prepare' methods, is implemented across all database interaction layers within the plugin's source code."
}
CVE-2026-96330: SQL Injection in tagDiv Opt-In (CRITICAL Severity, CVSS: 9.3) | Sceawere