Unauthenticated SQL Injection in Readabler Plugin by WordPress
CVE-2026-74015
9.3CRITICAL
What is CVE-2026-74015?
The Readabler plugin for WordPress, specifically versions prior to 2.0.18, is vulnerable to an unauthenticated SQL injection attack. This flaw allows attackers to execute arbitrary SQL queries against the database, potentially leading to unauthorized access to sensitive information. Website administrators using this plugin should take immediate action to update to the latest version to mitigate the risks associated with this vulnerability.
Affected Version(s)
Readabler < 2.0.18