Executive brief
Accessibility Press is a WordPress plugin that helps websites be more accessible to users with disabilities. A vulnerability allows administrators or developers to inadvertently inject malicious scripts into the site, which could be stored and executed for all visitors—potentially stealing login credentials, hijacking user accounts, or redirecting visitors to malicious sites.
Technical details
This is a stored cross-site scripting (XSS) vulnerability in the input validation logic of Accessibility Press versions up to 1.0.2. The plugin fails to properly sanitize or escape user-supplied input during web page generation, allowing an attacker with administrator or developer privileges to inject malicious JavaScript that persists in the database. When other users (including visitors) view the affected page, the malicious script executes in their browser context. Exploitation requires a privileged user to perform an action such as clicking a malicious link or submitting a crafted form. No official patch is currently available; affected sites should upgrade to a patched version or disable the plugin.
Affected products
- ikaes Accessibility Press through 1.0.2
Timeline
- 2025-09-30: disclosed: Reported by HunSec
- 2025-12-31: advisory: Published by Patchstack and registered as CVE-2025-49355