Impact
The flaw in the Themepoints Accordion plugin is an improper neutralization of input that results in stored cross‑site scripting. When malicious content is stored by the plugin, that content is later presented to all site visitors without proper HTML or JavaScript escaping. This flaw provides an attacker with the ability to inject and execute arbitrary client‑side code in the context of the website.
Affected Systems
The vulnerable product is the Themepoints Accordion WordPress plugin. All releases from the earliest known build (n/a) up to and including version 3.0.3 are affected. Site administrators should verify the installed plugin version and apply any available update.
Risk and Exploitability
The CVSS score of 5.9 classifies the vulnerability as medium severity. The EPSS score is lower than 1%, indicating a low current probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is external: an attacker can submit data that the plugin stores; the stored data is subsequently rendered in web pages viewed by any user. Exploitation requires the victim to load the affected page, at which point the malicious script runs in the victim’s browser.
OpenCVE Enrichment