What the vulnerability does
01Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WhileTrue Most And Least Read Posts Widget.This issue affects Most And Least Read Posts Widget: from n/a through 2.5.16.
Explanation of Vulnerability in Simple Terms
02Summary
The Most And Least Read Posts Widget for WordPress contains a SQL injection vulnerability in versions up to 2.5.16. An attacker with low-level WordPress access can craft malicious input to execute arbitrary SQL queries against the site database. This can expose sensitive data including user credentials and private content. A patched version has not been publicly identified.
What an attacker can do
03Attacker Capabilities
Read or modify database contents, including user passwords and private posts, by injecting SQL commands.
Potential impact on your site
04Site Impact
Unauthorized access to sensitive data, user credentials, and private content; potential data loss or corruption.
Conditions required to exploit
05Prerequisites
Attacker must have a low-privilege WordPress account (subscriber or contributor level or higher).
Key dates
06Disclosure timeline
December 31, 2023
CVE published
April 28, 2026
Record updated