VYPR

Pojo Accessibility

by WordPress

Source repositories

CVEs (2)

  • CVE-2026-2413HigMar 11, 2026
    risk 0.42cvss 7.5epss 0.02

    The Ally – Web Accessibility & Usability plugin for WordPress is vulnerable to SQL Injection via the URL path in all versions up to, and including, 4.0.3. This is due to insufficient escaping on the user-supplied URL parameter in the `get_global_remediations()` method, where…

  • CVE-2025-32640MedApr 9, 2025
    risk 0.31cvss 5.9epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Elementor Ally pojo-accessibility allows Stored XSS.This issue affects Ally: from n/a through <= 3.1.0.