CVE-2026-7467Disclosure

LOWCVSS 8.8 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

The Read More & Accordion plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.5.7. This is due to the 'RadMoreAjax::importData' function not restricting which database tables can be written to during import and not properly validating the imported data. This makes it possible for authenticated attackers, with permission granted by the site owner through the plugin's role settings, to insert arbitrary rows into the 'wp_users' and 'wp_usermeta' tables, including the 'wp_capabilities' field, allowing them to create a new administrator account and gain administrator access to the site.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-269

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-06-24); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-06-24: 1Mentions · 2026-08-26: 1PoC Mentioned / Linked · 2026-08-26: 1Technical Details · 2026-06-24: 1Technical Details · 2026-08-26: 106-2408-26
Signal classification1 categories
Disclosure
2100.0%
Referenced assets1 URL
By indicator
Full discourse2 posts
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2026-7467 - high 🚨 Read More & Accordion <= 3.5.7 - Authenticated Privilege Escalation > The Read More & Accordion (expand-maker) plugin for WordPress through 3.5.7 allows pr... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-7467 @pdnuclei #NucleiTemplates #cve

    Post summary

    The post announces the high‑severity CVE‑2026‑7467, noting an authenticated privilege escalation in the WordPress Read More & Accordion plugin (≤3.5.7) and links to a ProjectDiscovery library entry, but does not provide exploit code, reports active attacks, or mention patches.

    00012251
    1.2K followersView on X
  • Joey Romaine 🇺🇸 |=★=|@Tank23x0
    Disclosure

    CVE-2026-7467: high severity (CVSS 8.8). Read More & Accordion plugin for WordPress has a privilege escalation issue worth scoping now. Treat it like a small fire drill before it becomes a large one.

    Post summary

    The snippet announces CVE-2026-7467, noting its high severity and that it enables privilege escalation in the Accordion WordPress plugin.

    1000031
    340 followersView on X

Explore more