Description
The Accordions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Accordion body field in all versions up to, and including, 2.3.23 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Custom-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Published: 2026-06-09
Score: 6.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Accordions plugin contains an input validation flaw that allows an authenticated user with Custom‑level access or higher to inject malicious JavaScript into the accordion body field. The payload is persisted in the database and is rendered on every page where the accordion appears, causing the injected script to run in the browser context of any site visitor. This can be used to steal session cookies, deface the site, or redirect users to phishing pages.

Affected Systems

WordPress sites that have the Accordions plugin (pickplugins:Accordions) deployed, specifically versions up to and including 2.3.23. If the site uses a role with Custom+ privileges, that user can add the malicious payload to an accordion element.

Risk and Exploitability

The CVSS score of 6.4 reflects a medium severity risk, and the vulnerability is not listed in the CISA KEV catalog. While the EPSS score is not available, the requirement for authenticated Custom+ access limits the attack surface to users who already have significant privileges. An attacker who can access the edit interface can immediately inject a payload, which will then be executed for all users who view the modified accordion. The medium severity score and the required privilege level imply a moderate risk that should be addressed promptly.

Generated by OpenCVE AI on June 9, 2026 at 03:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Accordions plugin to the latest version (at least 2.3.24) to remove the input sanitization flaw.
  • If an upgrade is not immediately possible, block or remove the accordion functionality for Custom‑level and above users until the plugin can be patched.
  • Conduct a manual audit of all accordion entries to detect and delete any injected scripts and verify that no untrusted content remains visible to visitors.

Generated by OpenCVE AI on June 9, 2026 at 03:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 09 Jun 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 09 Jun 2026 05:15:00 +0000

Type Values Removed Values Added
First Time appeared Pickplugins
Pickplugins accordion
Wordpress
Wordpress wordpress
Vendors & Products Pickplugins
Pickplugins accordion
Wordpress
Wordpress wordpress

Tue, 09 Jun 2026 02:00:00 +0000

Type Values Removed Values Added
Description The Accordions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Accordion body field in all versions up to, and including, 2.3.23 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Custom-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Title Accordions <= 2.3.23 - Authenticated (Custom+) Stored Cross-Site Scripting via Accordion Body Field
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

Pickplugins Accordion
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-06-09T14:28:38.954Z

Reserved: 2026-06-04T13:34:48.823Z

Link: CVE-2026-10862

cve-icon Vulnrichment

Updated: 2026-06-09T14:28:31.180Z

cve-icon NVD

Status : Deferred

Published: 2026-06-09T02:16:22.977

Modified: 2026-06-09T13:33:34.393

Link: CVE-2026-10862

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-09T05:00:16Z

Weaknesses