Impact
An unauthenticated SQL injection flaw exists in WordPress Readabler plugin versions earlier than 2.0.18. The vulnerability arises from unsanitized user input that is directly concatenated into database queries, allowing attackers to inject arbitrary SQL statements. Because the flaw is unauthenticated, any user capable of sending HTTP requests to the plugin’s exposed URLs can exploit it, potentially leading to disclosure of sensitive data or modification of the WordPress database.
Affected Systems
This issue affects WordPress installations that have the Readabler plugin by merkulove installed in any version below 2.0.18. The plugin is typically used to improve content readability, but older versions contain the vulnerable injection point. Users should verify the plugin version through the WordPress admin interface or the installation directory.
Risk and Exploitability
The CVSS score of 9.3 indicates a high severity with broad impact. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog. Based on the description, it is inferred that the attack vector is remote via unauthenticated web requests to the plugin’s URLs. Although no public exploits have been confirmed, the high CVSS rating combined with the ability to read or alter the WordPress database underscores the need for an urgent fix.
OpenCVE Enrichment