cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches foraccordions-wp accordions-wp

Direction: ascending
Jun 07, 2024

Accordion # CVE-2023-47809

CVE, Research URL

CVE-2023-47809

Application

Accordion

Date
Nov 23, 2023
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themepoints Accordion plugin <= 2.6 versions.
Affected versions
max 2.7.
Status
vulnerable

Accordion # CVE-2023-5666

CVE, Research URL

CVE-2023-5666

Application

Accordion

Date
Oct 30, 2023
Research Description
The Accordion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'tcpaccordion' shortcode in all versions up to, and including, 2.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
max 2.7.
Status
vulnerable
Jan 11, 2026

Accordion # CVE-2025-69350

CVE, Research URL

CVE-2025-69350

Application

Accordion

Date
Jan 06, 2026
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themepoints Accordion accordions-wp allows Stored XSS.This issue affects Accordion: from n/a through <= 3.0.3.
Affected versions
max 3.0.3.
Status
vulnerable