
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-28115 is a Blind SQL Injection vulnerability in the WP Attractive Donations System – Easy Stripe & PayPal Donations WordPress plugin (plugin slug: WP_AttractiveDonationsSystem), developed by loopus. It affects all versions through and including 1.25. The vulnerability was disclosed on March 5, 2026, with the CVE received from Patchstack and a CVSS v3.1 score of 9.3 (Critical) assigned by CISA-ADP (Patchstack, NVD). NVD has noted this CVE is not currently prioritized for enrichment efforts.
The vulnerability is classified as CWE-89 (Improper Neutralization of Special Elements used in an SQL Command) and enables Blind SQL Injection attacks. The plugin fails to properly sanitize or parameterize user-supplied input before incorporating it into SQL queries, allowing an attacker to craft malicious input that alters query logic without receiving direct output — instead inferring database contents through boolean-based or time-based side channels. No authentication or user interaction is required, and the attack is conducted entirely over the network, with a Changed scope indicating impact can extend beyond the plugin itself to the underlying WordPress database (Patchstack, NVD).
Successful exploitation allows unauthenticated remote attackers to extract sensitive data from the WordPress database, including donor records, payment-related information, WordPress user credentials (hashed passwords), and other stored site data. The CVSS scope is rated as Changed, meaning the impact can extend beyond the vulnerable plugin component to the broader database environment. Availability may also be degraded through resource-intensive blind SQL queries, though integrity is not directly impacted (NVD, Patchstack).
As of the time of disclosure, there is no public proof-of-concept exploit code and no evidence of active in-the-wild exploitation (Feedly). The vulnerability does not require authentication, privileges, or user interaction, making it trivially exploitable if a working exploit were developed. The EPSS score is approximately 0.021% (0.000210), indicating a currently low probability of exploitation in the near term. The CVE is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.
/wp-content/plugins/WP_AttractiveDonationsSystem/readme.txt.' AND SLEEP(5)-- - can confirm injection if the server response is delayed.sqlmap with the identified endpoint and parameter to systematically extract database schema, table names, and sensitive data (e.g., sqlmap -u "https://target.com/[endpoint]?param=1" --dbs --batch).wp_users for credentials, plugin-specific tables for donation/payment records) to exfiltrate data for further exploitation or credential cracking.', --, AND, SLEEP, BENCHMARK, OR 1=1) in query parameters; abnormally slow HTTP responses suggesting time-based injection probing.SLEEP() or BENCHMARK() calls; unusual SELECT queries against wp_users or plugin-specific tables originating from the web application user.The primary remediation is to update the WP Attractive Donations System plugin to a version newer than 1.25; users should check the WordPress plugin repository for an available patched release (Patchstack). If no patched version is available, consider deactivating and removing the plugin until a fix is released. As interim mitigations, deploy a Web Application Firewall (WAF) with SQL injection detection rules, restrict access to plugin endpoints where possible, and monitor database activity for anomalous query patterns.
The vulnerability received brief automated coverage across security aggregation platforms including Vulners, CVEFeed, and VulDB shortly after disclosure. Social media mentions were observed on Mastodon and Bluesky via TheHackerWire, consistent with routine CVE broadcast activity rather than significant community discussion. No notable researcher commentary or vendor statements beyond the Patchstack advisory have been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."