Blind SQL Injection Vulnerability in TagDiv's Opt-In Builder Plugin
CVE-2023-3416
7.2HIGH
What is CVE-2023-3416?
The tagDiv Opt-In Builder plugin has a vulnerability that allows blind SQL injection through the 'subscriptionCouponId' parameter in the 'create_stripe_subscription' REST API endpoint. This weakness arises from insufficient escaping of user input and inadequate preparation of SQL queries. Authenticated attackers possessing administrator privileges can append malicious SQL commands to existing queries, which may lead to unauthorized access and extraction of sensitive information from the database. The vulnerability affects all versions up to and including 1.4.4, highlighting a significant security concern for users relying on this plugin.
Affected Version(s)
tagDiv Opt-In Builder * <= 1.4.4