WordPress Plugin Vulnerabilities

Accordion < 2.2.9 - Unprotected AJAX Action to Stored/Reflected XSS

Description

This flaw allowed any authenticated user with subscriber-level and above permissions the ability to import a new accordion and inject malicious Javascript as part of the accordion.

Proof of Concept

Affects Plugins

Fixed in 2.2.9

References

Classification

Type
XSS
CWE

Miscellaneous

Original Researcher
Chloe Chamberland
Submitter
Chloe Chamberland
Submitter website
Submitter twitter
Verified
No

Timeline

Publicly Published
2020-04-14 (about 5 years ago)
Added
2020-04-14 (about 5 years ago)
Last Updated
2020-05-29 (about 5 years ago)

Other