A vulnerability has been found in smub Charitable Plugin up to 1.8.12.1 on WordPress and classified as critical. The impacted element is an unknown function of the component Shortcode Handler. The manipulation of the argument order leads to sql injection. This vulnerability is uniquely identified as CVE-2026-77189. The attack is possible to be carried out remotely. No exploit exists.
WordPress
Vulnerability
CVE-2026-77189
VulDB
Apply vendor security patch