6 results (0.006 seconds)

CVSS: 6.5EPSS: 0%CPEs: 1EXPL: 0

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in PickPlugins Accordion accordions allows Stored XSS.This issue affects Accordion: from n/a through 2.2.99. The Accordion plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.2.99 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. • https://patchstack.com/database/vulnerability/accordions/wordpress-accordion-plugin-2-2-99-cross-site-scripting-xss-vulnerability?_s_id=cve • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 5.9EPSS: 0%CPEs: 1EXPL: 0

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Biplob Adhikari Accordions allows Stored XSS.This issue affects Accordions: from n/a through 2.3.5. Vulnerabilidad de neutralización incorrecta de la entrada durante la generación de páginas web (XSS o 'Cross-site Scripting') en Biplob Adhikari Accordions permite XSS almacenado. Este problema afecta a Accordions: desde n/a hasta 2.3.5. The Accordion – Multiple Accordion or FAQs Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.3.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. • https://patchstack.com/database/vulnerability/accordions-or-faqs/wordpress-accordions-plugin-2-3-5-cross-site-scripting-xss-vulnerability?_s_id=cve • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 5.9EPSS: 0%CPEs: 1EXPL: 0

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Biplob Adhikari Accordion – Multiple Accordion or FAQs Builder plugin <= 2.3.0 versions. The Accordions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via parameters and attributes such as 'label, 'type', 'sub-title', 'name' in versions up to, and including, 2.3.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with administrator-level access, and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. • https://patchstack.com/database/vulnerability/accordions-or-faqs/wordpress-accordions-multiple-accordions-or-faqs-builder-plugin-2-3-0-cross-site-scripting-xss?_s_id=cve • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 7.2EPSS: 0%CPEs: 1EXPL: 0

Auth. WordPress Options Change (siteurl, users_can_register, default_role, admin_email and new_admin_email) vulnerability in Biplob Adhikari's Accordions – Multiple Accordions or FAQs Builder plugin (versions <= 2.0.3 on WordPress. Una vulnerabilidad de Cambio de opciones autenticadas de WordPress (siteurl, users_can_register, default_role, admin_email y new_admin_email) vulnerabilidad en el plugin Accordions - Multiple Accordions o FAQs Builder de Biplob Adhikari (versiones anteriores a 2.0.3 incluyéndola) en WordPress The Accordions plugin for WordPress is vulnerable to arbitrary options update in versions up to, and including, 2.0.3. This is due to insufficient capability checking on the manual_import_json() function. This makes it possible for authenticated attackers to modify arbitrary options on the site and can be used for complete site takeover. • https://patchstack.com/database/vulnerability/accordions-or-faqs/wordpress-accordions-plugin-2-0-3-authenticated-wordpress-options-change-vulnerability?_s_id=cve https://wordpress.org/plugins/accordions-or-faqs/#developers • CWE-264: Permissions, Privileges, and Access Controls CWE-862: Missing Authorization •

CVSS: 5.5EPSS: 0%CPEs: 1EXPL: 0

Multiple Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerabilities in Accordions plugin <= 2.0.3 on WordPress via &addons-style-name and &accordions_or_faqs_license_key. Vulnerabilidad de Coss-Site Scripting (XSS) de autenticación múltiple (con permisos de admin o superiores) almacenada en el complemento Accordions en WordPress en versiones &lt;= 2.0.3 a través de &amp;addons-style-name y &amp;accordions_or_faqs_license_key. The Accordions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘license’ parameter used in the post_oxi_license function for the API class in versions up to, and including, 2.0.3 due to insufficient input sanitization and output escaping. This makes it possible for administrator-level attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page • https://patchstack.com/database/vulnerability/accordions-or-faqs/wordpress-accordions-plugin-2-0-3-multiple-auth-stored-cross-site-scripting-xss-vulnerabilities?_s_id=cve https://wordpress.org/plugins/accordions-or-faqs/#developers • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •