Authorization Bypass in Accordion and Accordion Slider Plugin for WordPress
CVE-2026-0727
5.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 14 February 2026
What is CVE-2026-0727?
The Accordion and Accordion Slider plugin for WordPress exhibits a serious authorization bypass vulnerability that impacts all versions up to and including 1.4.5. This flaw arises from the inadequate verification of user permissions in critical functions like 'wp_aas_save_attachment_data' and 'wp_aas_get_attachment_edit_form'. Consequently, authenticated attackers with contributor-level access or higher can exploit this weakness to read and manipulate attachment metadata, encompassing file paths, titles, captions, alt text, and custom links for any media attachment on the WordPress site, potentially leading to data exposure and unauthorized changes.
Affected Version(s)
Accordion and Accordion Slider 0 <= 1.4.5