Privilege Escalation Vulnerability in Read More & Accordion Plugin for WordPress
CVE-2026-7467
8.8HIGH
What is CVE-2026-7467?
The Read More & Accordion plugin for WordPress is susceptible to a privilege escalation attack that allows authenticated users to manipulate database entries improperly. The vulnerability arises from the 'RadMoreAjax::importData' function, which fails to impose restrictions on writable database tables. Consequently, authenticated attackers can potentially insert arbitrary rows into the 'wp_users' and 'wp_usermeta' tables, including modifications to the 'wp_capabilities' field, thereby enabling the creation of new administrator accounts and unauthorized access to the site.
Affected Version(s)
Read More & Accordion 0 <= 3.5.7