Executive brief
Charitable is a popular WordPress plugin for nonprofit fundraising and donation management. A SQL injection vulnerability in versions 1.8.12.1 and earlier allows subscriber-level users to read, modify, or delete the entire website database, including sensitive customer and donor information, potentially exposing payment records and personal data.
Technical details
This vulnerability is a SQL injection flaw exploitable by authenticated users with subscriber privileges. The injection point allows attackers to execute arbitrary SQL queries against the WordPress database without requiring administrative access. The attack requires user authentication at the subscriber level; no network-based attack vector without credentials. A successful exploit enables full database compromise: reading sensitive records, modifying transaction data, or deleting critical information. The vulnerability has been patched in version 1.8.12.2; administrators should update immediately.
Affected products
- Charitable Charitable <= 1.8.12.1
Timeline
- 2026-08-31: disclosed
- 2026-08-31: patched: Patch available in version 1.8.12.2