CVE-2026-74015: WordPress Readabler plugin < 2.0.18 - SQL Injection vulnerability
Published Aug 18, 2026
·Updated
Unauthenticated SQL Injection in Readabler < 2.0.18 versions.
Affected Software
1 affected component
WordPress Readabler plugin<2.0.18
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Readabler Pluginto a version that resolves this vulnerability.Fixed in 2.0.18
Event History
Aug 18, 2026
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
Which installations are affected?
Sites running Readabler versions earlier than 2.0.18 are affected. The issue is in the WordPress Readabler plugin.
2
What does an attacker need to exploit this?
An attacker does not need authentication or user interaction. The CVSS vector indicates the vulnerability is remotely reachable with low attack complexity.
3
What should I do to remediate the issue?
Update the Readabler plugin to version 2.0.18 or later. The provided data does not identify an alternative mitigation for environments that cannot update immediately.