WordPress Read More & Accordion Plugin Cross-Site Request Forgery Vulnerability
Vulnerability
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the Read More & Accordion plugin for WordPress, affecting all versions through 3.4.5. The vulnerability arises from inadequate nonce validation in the addNewButtons() function, allowing unauthenticated attackers to execute arbitrary PHP files by tricking a site administrator into clicking a link.
Impact
Exploitation of this vulnerability could lead to local file inclusion, allowing attackers to execute arbitrary PHP files on the server.
Reproduction
To reproduce this vulnerability, an attacker must exploit the missing nonce validation by sending a forged request that includes a link to be clicked by an administrator. This can be done by manipulating the addNewButtons() function to include malicious PHP code.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
