SQL Injection Vulnerability in Charitable Donation Platform for WordPress
CVE-2026-77189
6.5MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 1 September 2026
What is CVE-2026-77189?
The Charitable Donation & Fundraising Platform plugin for WordPress is susceptible to SQL Injection through the 'order' Shortcode Attribute, allowing authenticated users (contributor-level and above) to introduce additional SQL queries. This exploit results from inadequate escaping of user-supplied parameters and insufficient preparation of existing SQL queries, raising the risk of exposing sensitive database information. Notably, the [charitable_donors] shortcode is accessible to low-privileged users via draft or pending post previews, creating a potential entry point for exploitation.
Affected Version(s)
Charitable β Donation & Fundraising Platform (Donation Forms, Recurring Donations & Fundraising Campaigns) 0 <= 1.8.12.1