CVE-2026-28115: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2026-28115 is a Blind SQL Injection vulnerability in the WP Attractive Donations System – Easy Stripe & PayPal Donations WordPress plugin (plugin slug: WP_AttractiveDonationsSystem), developed by loopus. It affects all versions through and including 1.25. The vulnerability was disclosed on March 5, 2026, with the CVE received from Patchstack and a CVSS v3.1 score of 9.3 (Critical) assigned by CISA-ADP (Patchstack, NVD). NVD has noted this CVE is not currently prioritized for enrichment efforts.

Technical details

The vulnerability is classified as CWE-89 (Improper Neutralization of Special Elements used in an SQL Command) and enables Blind SQL Injection attacks. The plugin fails to properly sanitize or parameterize user-supplied input before incorporating it into SQL queries, allowing an attacker to craft malicious input that alters query logic without receiving direct output — instead inferring database contents through boolean-based or time-based side channels. No authentication or user interaction is required, and the attack is conducted entirely over the network, with a Changed scope indicating impact can extend beyond the plugin itself to the underlying WordPress database (Patchstack, NVD).

Impact

Successful exploitation allows unauthenticated remote attackers to extract sensitive data from the WordPress database, including donor records, payment-related information, WordPress user credentials (hashed passwords), and other stored site data. The CVSS scope is rated as Changed, meaning the impact can extend beyond the vulnerable plugin component to the broader database environment. Availability may also be degraded through resource-intensive blind SQL queries, though integrity is not directly impacted (NVD, Patchstack).

Exploitability

As of the time of disclosure, there is no public proof-of-concept exploit code and no evidence of active in-the-wild exploitation (Feedly). The vulnerability does not require authentication, privileges, or user interaction, making it trivially exploitable if a working exploit were developed. The EPSS score is approximately 0.021% (0.000210), indicating a currently low probability of exploitation in the near term. The CVE is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the WP Attractive Donations System plugin (version ≤ 1.25) using tools like WPScan, Shodan, or by checking publicly accessible plugin metadata at /wp-content/plugins/WP_AttractiveDonationsSystem/readme.txt.
  2. Identify vulnerable endpoint: Locate the plugin's front-end or AJAX-exposed functionality that accepts user-supplied parameters passed to SQL queries (e.g., donation form fields or query string parameters).
  3. Craft blind SQL injection payload: Inject boolean-based or time-based payloads into the vulnerable parameter. For example, a time-based payload such as ' AND SLEEP(5)-- - can confirm injection if the server response is delayed.
  4. Enumerate database contents: Use automated tools such as sqlmap with the identified endpoint and parameter to systematically extract database schema, table names, and sensitive data (e.g., sqlmap -u "https://target.com/[endpoint]?param=1" --dbs --batch).
  5. Extract sensitive data: Target WordPress core tables (e.g., wp_users for credentials, plugin-specific tables for donation/payment records) to exfiltrate data for further exploitation or credential cracking.

Indicators of compromise

  • Network: Unusual or repeated HTTP requests to plugin-related endpoints with SQL metacharacters (', --, AND, SLEEP, BENCHMARK, OR 1=1) in query parameters; abnormally slow HTTP responses suggesting time-based injection probing.
  • Logs: WordPress or web server access logs showing repeated requests to donation-related plugin endpoints with encoded or anomalous parameter values; database error messages in WordPress debug logs referencing SQL syntax errors.
  • Process/Database: Unexpected spikes in database CPU or query execution time consistent with SLEEP() or BENCHMARK() calls; unusual SELECT queries against wp_users or plugin-specific tables originating from the web application user.

Mitigation and workarounds

The primary remediation is to update the WP Attractive Donations System plugin to a version newer than 1.25; users should check the WordPress plugin repository for an available patched release (Patchstack). If no patched version is available, consider deactivating and removing the plugin until a fix is released. As interim mitigations, deploy a Web Application Firewall (WAF) with SQL injection detection rules, restrict access to plugin endpoints where possible, and monitor database activity for anomalous query patterns.

Community reactions

The vulnerability received brief automated coverage across security aggregation platforms including Vulners, CVEFeed, and VulDB shortly after disclosure. Social media mentions were observed on Mastodon and Bluesky via TheHackerWire, consistent with routine CVE broadcast activity rather than significant community discussion. No notable researcher commentary or vendor statements beyond the Patchstack advisory have been identified.

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management