plugin

Lightweight Accordion Vulnerabilities

6 known security issues reported for the Lightweight Accordion WordPress plugin. Most recent disclosed Dec 15, 2025.

3 medium

Running Lightweight Accordion on your site? Check whether your installed version is affected.

Scan your site free

Lightweight Accordion [lightweight-accordion] < 1.6.0

unknown

[en] The Lightweight Accordion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `lightweight-accordion` shortcode in all versions up to, and including, 1.5.20 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticate...

Affected:
up to 1.6.0
Fixed in:
1.6.0
Disclosed:
Dec 15, 2025

CVE-2025-13740 on NVD →

Lightweight Accordion <= 1.5.20 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Lightweight Accordion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `lightweight-accordion` shortcode in all versions up to, and including, 1.5.20 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated att...

CVSS:
6.4
Affected:
up to 1.5.20
Fixed in:
1.6.0
Disclosed:
Dec 14, 2025

CVE-2025-13740 on NVD →

Lightweight Accordion [lightweight-accordion] < 1.5.17

unknown

[en] The Lightweight Accordion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.5.16 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with cont...

Affected:
up to 1.5.17
Fixed in:
1.5.17
Disclosed:
Apr 9, 2024

CVE-2024-2436 on NVD →

Lightweight Accordion <= 1.5.16 - Authenticated(Contributor+) Stored Cross-Site Scripting via Shortcode

medium

The Lightweight Accordion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.5.16 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contribut...

CVSS:
6.4
Affected:
up to 1.5.16
Fixed in:
1.5.17
Disclosed:
Mar 22, 2024

CVE-2024-2436 on NVD →

Lightweight Accordion [lightweight-accordion] < 1.5.15

unknown

[en] The Lightweight Accordion WordPress plugin before 1.5.15 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

Affected:
up to 1.5.15
Fixed in:
1.5.15
Disclosed:
Feb 13, 2023

CVE-2023-0373 on NVD →

Lightweight Accordion <= 1.5.14 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

medium

The Lightweight Accordion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versions up to, and including, 1.5.14 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor l...

CVSS:
6.4
Affected:
up to 1.5.14
Fixed in:
1.5.15
Disclosed:
Jan 23, 2023

CVE-2023-0373 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database