SQL Injection Vulnerability in Charitable Plugin by WordPress
CVE-2026-81287
8.5HIGH
What is CVE-2026-81287?
The Charitable plugin for WordPress has a vulnerability that allows an attacker to exploit SQL Injection techniques in versions up to 1.8.12.1. This flaw could enable unauthorized access to sensitive database information by injecting malicious SQL statements through user input fields, potentially compromising the integrity and confidentiality of data. Website owners using affected versions are urged to apply security patches and updates to mitigate risks effectively.
Affected Version(s)
Charitable <= 1.8.12.1