Known vulnerabilities in Read and Understood
V2.3 Better sanitization of arguments coming in from POST and written to DB Better job using nonce. Uses relative address for plugin_url …
3Reported vulnerabilities
8.8Highest CVSS score
2.4Latest version
30+Active installs
What to do now
Update Read and Understood to 2.2 or later.
3 of these have a fixed version available. Updating resolves them.
This plugin has not been updated in over two years. New vulnerabilities may never be fixed. Consider an alternative.
Reported vulnerabilities
| CVE | Severity | Exploit probability |
Affected versions | Fixed in | Published |
|---|---|---|---|---|---|
| CVE-2018-5669 | High | 0.6% | 2.1 to 2.1 (inclusive) | 2.2 |
January 13, 2018 |
| CVE-2018-5668 | Medium | 0.7% | 2.1 to 2.1 (inclusive) | 2.2 |
January 13, 2018 |
| CVE-2018-5667 | Medium | 0.7% | 2.1 to 2.1 (inclusive) | 2.2 |
January 13, 2018 |