Show filters
38 Total Results
Displaying 31-38 of 38
Sort by:
Attacker Value
Unknown
CVE-2023-1891
Disclosure Date: June 27, 2023 (last updated October 08, 2023)
The Accordion & FAQ WordPress plugin before 1.9.9 does not escape various generated URLs, before outputting them in attributes when some notices are displayed, leading to Reflected Cross-Site Scripting
0
Attacker Value
Unknown
CVE-2023-0373
Disclosure Date: February 13, 2023 (last updated October 08, 2023)
The Lightweight Accordion WordPress plugin before 1.5.15 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
0
Attacker Value
Unknown
CVE-2022-4781
Disclosure Date: January 30, 2023 (last updated October 08, 2023)
The Accordion Shortcodes WordPress plugin through 2.4.2 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.
0
Attacker Value
Unknown
CVE-2022-4487
Disclosure Date: January 16, 2023 (last updated October 08, 2023)
The Easy Accordion WordPress plugin before 2.2.0 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.
0
Attacker Value
Unknown
CVE-2021-24576
Disclosure Date: October 11, 2021 (last updated February 23, 2025)
The Easy Accordion WordPress plugin before 2.0.22 does not properly sanitize inputs when adding new items to an accordion.
0
Attacker Value
Unknown
CVE-2021-24283
Disclosure Date: May 14, 2021 (last updated February 22, 2025)
The tab GET parameter of the settings page is not sanitised or escaped when being output back in an HTML attribute, leading to a reflected XSS issue.
0
Attacker Value
Unknown
CVE-2020-13644
Disclosure Date: May 28, 2020 (last updated February 21, 2025)
An issue was discovered in the Accordion plugin before 2.2.9 for WordPress. The unprotected AJAX wp_ajax_accordions_ajax_import_json action allowed any authenticated user with Subscriber or higher permissions the ability to import a new accordion and inject malicious JavaScript as part of the accordion.
0
Attacker Value
Unknown
CVE-2015-4365
Disclosure Date: June 15, 2015 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the Taxonomy Accordion module for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via vectors related to taxonomy terms.
0