The Accordion Slider plugin for WordPress has a security issue where attackers can insert harmful code into a webpage using the ‘html’ attribute of an accordion slider. This can only be done by users with Contributor-level access or higher, and only if an Administrator-level user has given them access through the plugin’s settings.