Description
Unrestricted Upload of File with Dangerous Type vulnerability in Ability, Inc Accessibility Suite online-accessibility allows Stored XSS.This issue affects Accessibility Suite: from n/a through <= 4.18.
Published: 2025-04-10
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability allows an attacker to upload a file of a dangerous type through the Accessibility Suite plugin’s upload interface. The uploaded file is stored on the server without proper validation and later executed in the context of the site, resulting in a stored cross‑site scripting (XSS) flaw. As a consequence, an attacker can inject malicious scripts that run in the browsers of visitors, potentially hijacking user sessions, defacing content, or stealing credentials. The weakness is categorized as CWE‑434, an unchecked file type upload leading to a stored XSS.

Affected Systems

The vulnerability affects Ability, Inc’s Accessibility Suite plugin version 4.18 and earlier. Any WordPress installation that has this plugin installed and has not been updated to a newer version is potentially compromised.

Risk and Exploitability

With a CVSS score of 6.5 the flaw is considered moderately severe, while an EPSS score of less than 1% indicates a very low probability of exploitation in the wild at this time. The vulnerability is currently not listed in the CISA KEV catalog, further suggesting it has not been observed in widespread attacks. The attack vector is inferred to be the plugin’s file‑upload endpoint, likely requiring authentication to perform the upload, but the vulnerability allows the uploaded file to be accessed by any visitor, expanding the impact. The overall risk remains moderate, warranting timely remediation to prevent a stored XSS event.

Generated by OpenCVE AI on April 30, 2026 at 23:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest update for Accessibility Suite (version 4.19 or later) to eliminate the arbitrary file upload vulnerability.
  • If an update cannot be performed immediately, restrict upload permissions so that only trusted administrators can upload files and enable monitoring of the plugin’s upload directory for unexpected content.
  • Configure site defenses such as a web application firewall or strict MIME type checks to block dangerous file types and enforce proper file‑type validation before storage.

Generated by OpenCVE AI on April 30, 2026 at 23:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-10467 Unrestricted Upload of File with Dangerous Type vulnerability in Ability, Inc Accessibility Suite by Online ADA allows Stored XSS. This issue affects Accessibility Suite by Online ADA: from n/a through 4.18.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Unrestricted Upload of File with Dangerous Type vulnerability in Ability, Inc Accessibility Suite by Online ADA allows Stored XSS. This issue affects Accessibility Suite by Online ADA: from n/a through 4.18. Unrestricted Upload of File with Dangerous Type vulnerability in Ability, Inc Accessibility Suite online-accessibility allows Stored XSS.This issue affects Accessibility Suite: from n/a through <= 4.18.
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Thu, 10 Apr 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 10 Apr 2025 08:15:00 +0000

Type Values Removed Values Added
Description Unrestricted Upload of File with Dangerous Type vulnerability in Ability, Inc Accessibility Suite by Online ADA allows Stored XSS. This issue affects Accessibility Suite by Online ADA: from n/a through 4.18.
Title WordPress Accessibility Suite plugin <= 4.18 - Arbitrary File Upload vulnerability
Weaknesses CWE-434
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:19.134Z

Reserved: 2025-04-04T10:01:42.464Z

Link: CVE-2025-32215

cve-icon Vulnrichment

Updated: 2025-04-10T19:08:57.488Z

cve-icon NVD

Status : Deferred

Published: 2025-04-10T08:15:18.803

Modified: 2026-04-23T15:28:46.300

Link: CVE-2025-32215

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T23:30:03Z

Weaknesses