Impact
Subscriber Cross Site Scripting in the WordPress Accordion plugin (versions ≤ 3.0.6) lets attackers embed malicious JavaScript that is executed when visitors view pages containing the plugin. The flaw arises when untrusted user input is rendered by the plugin without proper sanitization or escaping, enabling stored or reflected script injection.
Affected Systems
Sites that have installed the Themepoints Accordion plugin, specifically any version up to and including 3.0.6, are impacted. No other vendor or product names are listed in the CNA data, so the vulnerability applies to all configurations where the plugin outputs potentially user‑controlled content.
Risk and Exploitability
The CVSS score of 6.5 indicates medium severity, and the EPSS score is not provided. The vulnerability is not in the CISA KEV catalog. Likely attack vectors involve an attacker inserting script payloads through plugin shortcodes or input fields that are later displayed without adequate filtering, potentially leading to defacement, cookie theft, or phishing attempts. Overall risk to confidentiality, integrity, and availability is moderate with a moderate probability of exploitation.
OpenCVE Enrichment