Input validation vulnerability in Accordion – Multiple Accordion or FAQs Builder 2.0.3

. The Accordions WordPress plugin has a security vulnerability that could allow an attacker with administrator-level access to inject malicious web scripts into pages. If a user were to access one of these injected pages, it would execute the malicious scripts. This vulnerability affects all versions of the plugin up to and including version 2.0.3, because the input for the Bootstrap class constructor function does not have proper input sanitation or output escaping.

Detected in:

Accordion – Multiple Accordion or FAQs Builder open vulnerable versions: >= * <= 2.0.3

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.