VYPR
High severity7.1NVD Advisory· Published Jun 2, 2026· Updated Jun 2, 2026

CVE-2025-52759

CVE-2025-52759

Description

Reflected XSS vulnerability in Accordion FAQ plugin (versions up to 2.2.1) allows attackers to inject malicious scripts.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Reflected XSS vulnerability in Accordion FAQ plugin (versions up to 2.2.1) allows attackers to inject malicious scripts.

Vulnerability

An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists in the UnboundStudio Accordion FAQ plugin. This issue allows for Reflected XSS and affects versions from n/a through 2.2.1 [1].

Exploitation

Exploitation requires user interaction, such as a privileged user clicking a malicious link, visiting a crafted page, or submitting a form [1].

Impact

A successful attack could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into the website. These scripts would then be executed when guests visit the site, potentially leading to various malicious actions [1].

Mitigation

Users are advised to update the affected plugin to a version later than 2.2.1. If an update is not immediately possible, users should seek assistance from their hosting provider or web developer. Patchstack has issued a mitigation rule to block attacks until an official patch can be safely applied [1].

AI Insight generated on Jun 2, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

3

Patches

0

No patches discovered yet.

Vulnerability mechanics

No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.

References

1

News mentions

1