Impact
The Accordion Slider plugin for WordPress includes a stored XSS vulnerability caused by improper neutralization of user input during web page generation. The flaw allows an attacker to inject malicious scripts that will execute in the browsers of any user viewing a slider that contains the injected content. Because the payload is stored, it persists across requests and can be used for credential theft, defacement, or delivery of further malware. This weakness is classified as CWE‑79.
Affected Systems
The vulnerability affects the bqworks Accordion Slider plugin for WordPress. All installed instances with a version of 1.9.13 or earlier are potentially impacted. No later version information is provided, so any current installation should be inspected for a version number and considered at risk if it falls within this range.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity, while the EPSS score of less than 1 % shows a low probability of exploitation at the time of analysis. The vulnerability is not listed in CISA’s KEV catalog. Attackers would likely exploit the flaw by creating or editing slider content through the plugin’s interface or by supplying crafted data that is stored and later rendered. Successful exploitation would give the attacker access to the victim’s browsing session and could lead to further session hijacking or data compromise.
OpenCVE Enrichment