Cross-Site Request Forgery Vulnerability in Read More & Accordion Plugin for WordPress
CVE-2025-0810

7.5HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
5 April 2025

What is CVE-2025-0810?

The Read More & Accordion plugin for WordPress is susceptible to Cross-Site Request Forgery due to inadequate nonce validation within the addNewButtons() function. This flaw allows unauthenticated attackers to execute unauthorized actions by tricking site administrators into clicking a malicious link, potentially leading to the execution of arbitrary PHP files.

Affected Version(s)

Read More & Accordion * <= 3.4.5

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Bassem Essam
.