Impact
The Readabler WordPress plugin contains an unauthenticated SQL Injection flaw caused by inadequate escaping of a user‑supplied parameter and the absence of proper query preparation. Because this vulnerability can be triggered by any visitor to the site, attackers can inject additional SQL code into existing queries and retrieve sensitive database contents, including user credentials and private data. The weakness is classified as CWE‑89.
Affected Systems
All installations of Readabler for WordPress versions earlier than 2.0.18 are affected. The flaw exists in every release up to but not including 2.0.18, regardless of the WordPress site version or other plugins present.
Risk and Exploitability
The CVSS score of 7.5 places the vulnerability in the high severity range, indicating a non‑trivial risk to confidentiality and data integrity. An EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, but the lack of authentication controls and the public nature of the injection surface make exploitation likely via automated web requests. Attackers can mount the exploit simply by crafting a malicious URL or payload and sending it to the vulnerable endpoint, with no pre‑existing credentials required.
OpenCVE Enrichment