S4E just found a high top 10 tcp port service scan
high·Product Based Web Vulnerabilities·Updated Aug 30, 2026

CVE-2026-7467 Scanner

CVE-2026-7467 Scanner - Privilege Escalation vulnerability in Read More & Accordion (WordPress Plugin)

Est. Time~1 minutes
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
3
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2026-7467
8.8
CVSShigh
Exploitable remotely over the internet · low-privilege account sufficient.

The Read More & Accordion plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.5.7. This is due to the 'RadMoreAjax::importData' function not restricting which database tables can be written to during import and not properly validating the imported data. This makes it possible for authenticated attackers, with permission granted by the site owner through the plugin's role settings, to insert arbitrary rows into the 'wp_users' and 'wp_usermeta' tables, including the 'wp_capabilities' field, allowing them to create a new administrator account and gain administrator access to the site.

Attack Vector
Network
Privileges Req.
Low
User Interaction
None
Affected
Read More & Accordionby edmonparker
0
Updated Aug 26, 2026View on NVD →
Detail

The Read More & Accordion plugin for WordPress is widely used by site administrators and web developers to manage content displayed on their websites. The plugin simplifies content management by providing features like expandable sections and accordions, making websites more dynamic and engaging for visitors. It is utilized across various industry verticals for enhancing user experience on WordPress sites. Web developers often prefer it because of its easy integration and configuration with existing WordPress frameworks. However, like many plugins, it requires regular updates and monitoring to maintain website security.

Privilege Escalation is a critical vulnerability that allows unauthorized elevation of access privileges within a system. Attackers exploiting this vulnerability can gain control over higher access levels, allowing them to perform restricted actions. In the context of WordPress plugins, privilege escalation can lead to malicious activities such as creating admin accounts without authorization. The vulnerability is often exploited through improper validation checks, enabling attackers to bypass regular access restrictions.

The vulnerability in the Read More & Accordion plugin arises from improper validation in the importData AJAX handler. Specifically, the yrm_import_data action allows authenticated users with plugin access to upload a crafted JSON attachment. This exploit can insert arbitrary rows into WordPress database tables. The primary concern is the potential modification of tables controlling user roles and capabilities, facilitating the creation of new administrator accounts. This unchecked data import process is the core technical flaw allowing privilege escalation.

When exploited, this vulnerability could result in the complete takeover of a WordPress site. By creating unauthorized administrator accounts, malicious users can perform all actions available to legitimate administrators, including modifying site content, installing malicious plugins, or locking out legitimate users. This can lead to data leaks, defacement, and loss of site integrity. Therefore, it is essential for site administrators to secure this endpoint promptly to prevent such unauthorized escalations.

REFERENCES

Solution Advice
  • Update the Read More & Accordion plugin to the latest version to patch the vulnerability.
  • Review user account privileges to ensure no unauthorized users have been added as administrators.
  • Regularly monitor plugin updates and apply them timely to mitigate potential threats.
  • Consider implementing additional validation and access restrictions for plugin-related actions.
  • Conduct regular audits of your WordPress installation for potential vulnerabilities.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.