plugin

Easy Accordion Free Vulnerabilities

8 known security issues reported for the Easy Accordion Free WordPress plugin. Most recent disclosed Aug 7, 2026.

5 medium

Running Easy Accordion Free on your site? Check whether your installed version is affected.

Scan your site free

Easy Accordion <= 3.1.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'accordionTitleTag' Block Attribute

medium

The Easy Accordion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'accordionTitleTag' block attribute in versions up to, and including, 3.1.8. This is due to insufficient input sanitization and output escaping in the accordion_header_renderer() function, which emits the attacker-supplied tag...

CVSS:
6.4
Affected:
up to 3.1.8
Fixed in:
3.1.9
Disclosed:
Aug 7, 2026

CVE-2026-18988 on NVD →

Easy Accordion <= 3.1.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'align' Block Attribute

medium

The Easy Accordion – AI-Powered FAQ & Accordion Blocks, Product FAQ plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'align' Block Attribute in all versions up to, and including, 3.1.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, wi...

CVSS:
6.4
Affected:
up to 3.1.6
Fixed in:
3.1.7
Disclosed:
Jul 15, 2026

CVE-2026-15652 on NVD →

Easy Accordion – Responsive Accordion FAQ Builder and Product FAQ [easy-accordion-free] < 2.3.5

unknown

[en] The Easy Accordion – Best Accordion FAQ Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'accordion_content_source' attribute in all versions up to, and including, 2.3.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticate...

Affected:
up to 2.3.5
Fixed in:
2.3.5
Disclosed:
Mar 13, 2024

CVE-2024-1363 on NVD →

Easy Accordion – Best Accordion FAQ Plugin for WordPress <= 2.3.4 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Easy Accordion – Best Accordion FAQ Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'accordion_content_source' attribute in all versions up to, and including, 2.3.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated att...

CVSS:
6.4
Affected:
up to 2.3.4
Fixed in:
2.3.5
Disclosed:
Mar 8, 2024

CVE-2024-1363 on NVD →

Easy Accordion – Responsive Accordion FAQ Builder and Product FAQ [easy-accordion-free] < 2.2.0

unknown

[en] The Easy Accordion WordPress plugin before 2.2.0 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as a...

Affected:
up to 2.2.0
Fixed in:
2.2.0
Disclosed:
Jan 16, 2023

CVE-2022-4487 on NVD →

Easy Accordion <= 2.1.20 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

medium

The Easy Accordion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in versions up to, and including, 2.1.20 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor level and...

CVSS:
6.4
Affected:
up to 2.1.20
Fixed in:
2.2.0
Disclosed:
Dec 23, 2022

CVE-2022-4487 on NVD →

Easy Accordion – Responsive Accordion FAQ Builder and Product FAQ [easy-accordion-free] < 2.0.22

unknown

[en] The Easy Accordion WordPress plugin before 2.0.22 does not properly sanitize inputs when adding new items to an accordion.

Affected:
up to 2.0.22
Fixed in:
2.0.22
Disclosed:
Oct 11, 2021

CVE-2021-24576 on NVD →

Easy Accordion <= 2.0.21 - Authenticated Stored Cross-Site Scripting

medium

The Easy Accordion WordPress plugin before 2.0.22 does not properly sanitize inputs when adding new items to an accordion.

CVSS:
6.4
Affected:
up to 2.0.21
Fixed in:
2.0.22
Disclosed:
Sep 10, 2021

CVE-2021-24576 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database