VYPR

Lightweight Accordion

by WordPress

Source repositories

CVEs (3)

  • CVE-2024-2436MedApr 9, 2024
    risk 0.42cvss 6.4epss 0.00

    The Lightweight Accordion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.5.16 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible…

  • CVE-2025-13740MedDec 15, 2025
    risk 0.35cvss 6.4epss 0.00

    The Lightweight Accordion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `lightweight-accordion` shortcode in all versions up to, and including, 1.5.20 due to insufficient input sanitization and output escaping on user supplied attributes.…

  • CVE-2023-0373MedFeb 13, 2023
    risk 0.35cvss 5.4epss 0.01

    The Lightweight Accordion WordPress plugin before 1.5.15 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting…