Impact
The stored XSS flaw arises from improper neutralization of user input in the Smooth Accordion plugin. Malicious JavaScript can be inserted into accordion content and persist in the database. When an ordinary visitor loads a page containing the compromised accordion, the injected script runs in that visitor’s browser, which can lead to session hijacking, cookie theft, or site defacement. The weakness is consistent with CWE‑79, a classic input validation and output encoding issue.
Affected Systems
The vulnerability affects all releases of Zakir Smooth Accordion for WordPress up to and including version 2.1. Any site that has installed one of these versions of the plugin is at risk, regardless of its configuration.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, while the EPSS score of less than 1 % suggests a low current likelihood of exploitation. The flaw is not listed in the CISA KEV catalog, meaning no widespread exploits have been reported. To exploit it, an attacker generally needs the ability to add or edit accordion content with sufficient privileges. If a site allows unauthenticated users to create or edit accordions, the risk expands to all visitors. Sites with restricted editing rights are still subject to threat through compromised authors or administrators.
OpenCVE Enrichment
EUVD