External risk intelligence

tagDiv Opt-In Builder SQL Injection Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2026-96330

The vulnerability affects a WordPress plugin designed for subscription and opt-in forms. Such plugins are typically deployed on public-facing web servers to interact with site visitors, making the vulnerable input fields commonly accessible via the public internet.

SQL Injection

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This vulnerability involves a weakness in how a specific software component handles data, potentially allowing unauthorized access to information. The primary concern is to determine if this component is in use and, if so, to understand the potential exposure.

  • Flaw allows unauthorized data access.
  • Could impact customer data privacy.
  • Confirm use and assess related risks.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by sending specially crafted input through a web interface that is exposed to the network. This input would target the tagDiv Opt-In Builder's subscription feature, leading to a blind SQL injection. If successful, an attacker could potentially retrieve sensitive data from the database or cause disruptions to the service.

  • Entry condition: Publicly accessible web interface.
  • Trigger point: Sending malicious input to subscription forms.
  • Resulting risk: Database information disclosure and service disruption.

Live Threat

Current exploitation, exposure, and threat context

A SQL Injection vulnerability in the tagDiv Opt-In Builder's td-subscription component could allow an attacker to execute arbitrary SQL commands. This could occur when the application does not properly neutralize special elements in SQL commands, potentially leading to unintended database access or manipulation under specific conditions supported by the advisory.

  • Sensitive database information.
  • Via crafted input to subscription forms.
  • Potential for unauthorized data access.

Operational Fix

Recommended remediation, mitigation, and detection steps

Application owners and potentially platform teams are likely responsible for addressing this SQL injection vulnerability in the tagDiv Opt-In Builder. The initial step is to locate all instances of the affected plugin, determine their business criticality and network exposure, and then identify the accountable owner before planning remediation.

  • Identify affected plugin instances.
  • Verify public reachability and criticality.
  • Plan remediation with accountable owner.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the tagDiv Opt-In Builder plugin?

It is a WordPress plugin designed to help website owners create and manage subscription and email opt-in forms. These forms are typically embedded into web pages to capture visitor information, which is then processed and stored within the site's connected database.

What does CVE-2026-96330 mean for software security?

This vulnerability is classified as CWE-89, or SQL Injection. It occurs when a program fails to properly clean user-provided data before including it in a database query. In this case, an attacker could manipulate these queries to access or extract sensitive information from the database that they are not authorized to view.

How is this vulnerability triggered?

An attacker triggers this flaw by sending specially crafted input into the subscription forms managed by the plugin. It is important to note that the vulnerability specifically targets the processing of these inputs; simply viewing a page containing the form does not trigger the bug. The malicious activity must be submitted through the form interface to influence the underlying database command.

Is my site at risk according to Halo Surface Signal?

Because this plugin is intended for public-facing subscription and opt-in forms, it is inherently designed to be accessible via the internet. Halo Surface Signal identifies this as a higher-risk scenario because an attacker does not need special network access or credentials to interact with these forms, potentially allowing them to reach the vulnerable component from anywhere.

What should I do first to address CVE-2026-96330?

Start by conducting an inventory of your WordPress installations to confirm if the tagDiv Opt-In Builder plugin is present and active. Once you have identified where it is running, evaluate the business criticality of those specific sites and determine who is responsible for managing them. This will allow your team to coordinate the necessary updates to secure your data.

References