Time-based Blind SQL Injection in Read More & Accordion Plugin for WordPress
CVE-2026-7472
4.9MEDIUM
What is CVE-2026-7472?
The Read More & Accordion plugin for WordPress is susceptible to time-based blind SQL Injection through the 'orderby' parameter. This vulnerability is caused by improper handling of user input in database queries, wherein the esc_sql() function is applied without encapsulating the value in quotes. As a result, an attacker can leverage this flaw to inject arbitrary SQL commands, gaining unauthorized access to sensitive information from the database, including administrator credentials. This vulnerability affects all versions up to 3.5.7, necessitating immediate patching for all sites utilizing this plugin.
Affected Version(s)
Read More & Accordion 0 <= 3.5.7