An issue was discovered in the Accordion plugin before 2.2.9 for WordPress. The unprotected AJAX wp_ajax_accordions_ajax_import_json action allowed any authenticated user with Subscriber or higher permissions the ability to import a new accordion and inject malicious JavaScript as part of the accordion.
Advisories
Source ID Title
EUVD EUVD EUVD-2020-5886 An issue was discovered in the Accordion plugin before 2.2.9 for WordPress. The unprotected AJAX wp_ajax_accordions_ajax_import_json action allowed any authenticated user with Subscriber or higher permissions the ability to import a new accordion and inject malicious JavaScript as part of the accordion.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-04T12:25:16.466Z

Reserved: 2020-05-27T00:00:00

Link: CVE-2020-13644

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-05-28T04:15:13.457

Modified: 2024-11-21T05:01:40.153

Link: CVE-2020-13644

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses