Read More & Accordion <= 3.5.7 - Authenticated Privilege Escalation
CVE-2026-7467
Verified
Description
The Read More & Accordion (expand-maker) plugin for WordPress through 3.5.7 allows privilege escalation due to improper validation in the importData AJAX handler (yrm_import_data action). An authenticated user with plugin access can upload a crafted JSON attachment to insert arbitrary rows into WordPress database tables, including those that control user roles and capabilities, potentially leading to site takeover.
Severity
High
CVSS Score
8.8
Exploit Probability
1%
Affected Product
expand-maker
Published Date
July 19, 2026
Template Author
zer0p0int
CVE-2026-7467.yaml
8.8Score
CVSS Metrics
CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVE ID:
cve-2026-7467
CWE ID:
cwe-269
Remediation Steps
Update to the latest version of the Read More & Accordion (expand-maker) plugin.