What the vulnerability does
01Description
Auth. WordPress Options Change (siteurl, users_can_register, default_role, admin_email and new_admin_email) vulnerability in Biplob Adhikari's Accordions – Multiple Accordions or FAQs Builder plugin (versions <= 2.0.3 on WordPress.
Explanation of Vulnerability in Simple Terms
02Summary
The Accordions plugin for WordPress versions up to 2.0.3 contains an authorization flaw that allows high-privilege users to read sensitive data, modify site content, or disrupt service. The vulnerability requires an authenticated admin or editor account to exploit. Site owners should update immediately to a version newer than 2.0.3.
What an attacker can do
03Attacker Capabilities
Read sensitive data, modify content, or disrupt the site if they have admin or editor access.
Potential impact on your site
04Site Impact
Compromised admin or editor accounts can access confidential information and alter site functionality.
Conditions required to exploit
05Prerequisites
Attacker must have high-level WordPress user privileges (admin or editor role).
Key dates
06Disclosure timeline
October 21, 2022
CVE published
April 28, 2026
Record updated