/Vulnerability Library

Read More & Accordion <= 3.5.7 - Authenticated Privilege Escalation

CVE-2026-7467
Verified

Description

The Read More & Accordion (expand-maker) plugin for WordPress through 3.5.7 allows privilege escalation due to improper validation in the importData AJAX handler (yrm_import_data action). An authenticated user with plugin access can upload a crafted JSON attachment to insert arbitrary rows into WordPress database tables, including those that control user roles and capabilities, potentially leading to site takeover.

Severity

High

CVSS Score

8.8

Exploit Probability

1%

Affected Product

expand-maker

Published Date

July 19, 2026

Template Author

zer0p0int

CVE-2026-7467.yaml
8.8Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVE ID:
cve-2026-7467
CWE ID:
cwe-269

References

https://www.wordfence.com/threat-intel/vulnerabilities/id/adf51c03-b0bb-4864-b64d-6b0cba4b0130https://wordpress.org/plugins/expand-maker/https://nvd.nist.gov/vuln/detail/CVE-2026-7467

Remediation Steps

Update to the latest version of the Read More & Accordion (expand-maker) plugin.