{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/readabler-plugin/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-78576"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Readabler Plugin"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eThe Readabler plugin for WordPress contains an unauthenticated SQL injection vulnerability (CVE-2026-78576) affecting all versions prior to 2.0.18. The flaw exists due to improper input sanitization and a lack of parameterized queries when handling user-supplied parameters. Because the vulnerability is reachable without authentication, remote, unauthenticated attackers can manipulate SQL queries executed by the application. Successful exploitation enables the exfiltration of sensitive information from the site's database, posing a high risk to data confidentiality. Organizations utilizing the Readabler plugin are advised to verify their installed version and upgrade to 2.0.18 or higher to remediate this vulnerability.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to perform SQL injection attacks, leading to unauthorized access to sensitive database information. This may include user credentials, configuration details, or other private data stored within the WordPress database. Given the ubiquity of WordPress installations, this vulnerability represents a significant risk for organizations managing public-facing web infrastructure.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the Readabler plugin for WordPress to version 2.0.18 or later immediately.\u003c/li\u003e\n\u003cli\u003eAudit web server access logs for anomalous HTTP requests containing SQL keywords (e.g., SELECT, UNION, SLEEP) targeting WordPress plugin endpoints.\u003c/li\u003e\n\u003cli\u003eDeploy the Sigma rule provided below to monitor for potential SQL injection patterns targeting web applications.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-25T12:08:17Z","date_published":"2026-08-25T12:08:17Z","id":"https://feed.craftedsignal.io/briefs/2026-08-readabler-sqli/","summary":"The Readabler WordPress plugin is vulnerable to unauthenticated SQL injection in versions prior to 2.0.18, allowing remote attackers to extract sensitive database content.","title":"SQL Injection in Readabler Plugin for WordPress","url":"https://feed.craftedsignal.io/briefs/2026-08-readabler-sqli/"}],"language":"en","title":"CraftedSignal Threat Feed - Readabler Plugin","version":"https://jsonfeed.org/version/1.1"}