Time-based Blind SQL Injection in Read More & Accordion Plugin for WordPress
CVE-2026-7472

4.9MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
20 May 2026

What is CVE-2026-7472?

The Read More & Accordion plugin for WordPress is susceptible to time-based blind SQL Injection through the 'orderby' parameter. This vulnerability is caused by improper handling of user input in database queries, wherein the esc_sql() function is applied without encapsulating the value in quotes. As a result, an attacker can leverage this flaw to inject arbitrary SQL commands, gaining unauthorized access to sensitive information from the database, including administrator credentials. This vulnerability affects all versions up to 3.5.7, necessitating immediate patching for all sites utilizing this plugin.

Affected Version(s)

Read More & Accordion 0 <= 3.5.7

References

CVSS V3.1

Score:
4.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

BIMA IKHSAN
.