VYPR

Read More & Accordion

by WordPress

CVEs (6)

  • CVE-2026-7467HigMay 20, 2026
    risk 0.57cvss 8.8epss 0.00

    The Read More & Accordion plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.5.7. This is due to the 'RadMoreAjax::importData' function not restricting which database tables can be written to during import and not properly…

  • CVE-2023-3392HigOct 16, 2023
    risk 0.47cvss 7.2epss 0.01

    The Read More & Accordion WordPress plugin before 3.2.7 unserializes user input provided via the settings, which could allow high-privilege users such as admin to perform PHP Object Injection when a suitable gadget is present.

  • CVE-2025-0810HigApr 5, 2025
    risk 0.42cvss 7.5epss 0.00

    The Read More & Accordion plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.4.7. This is due to missing or incorrect nonce validation on the addNewButtons() function. This makes it possible for unauthenticated attackers to…

  • CVE-2026-7472MedMay 20, 2026
    risk 0.32cvss 4.9epss 0.00

    The Read More & Accordion plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'orderby' parameter in all versions up to, and including, 3.5.7. This is due to the use of esc_sql() without surrounding the value in quotes in an ORDER BY clause inside the…

  • CVE-2025-64247MedDec 16, 2025
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in edmon.parker Read More & Accordion expand-maker allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Read More & Accordion: from n/a through <= 3.5.5.1.

  • CVE-2024-13639MedFeb 13, 2025
    risk 0.21cvss 4.3epss 0.00

    The Read More & Accordion plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on the expmDeleteData() function in all versions up to, and including, 3.4.2. This makes it possible for authenticated attackers, with…