Junglewise Threat Intelligence

CVE-2026-100751: Regular Labs Tabs & Accordions Pro stored XSS via URL attributes

CVE-2026-100751 · Severity: info · Published 2026-09-28

Vendors: Regular Labs.

Executive brief

Tabs & Accordions Pro, a Joomla extension for creating tabbed and accordion content, contains a stored cross-site scripting (XSS) vulnerability that allows authenticated administrators to inject malicious JavaScript. When a tab or accordion item's URL option is configured with a JavaScript scheme (javascript:), the extension fails to sanitize it before rendering, causing the script to execute in users' browsers. This could lead to session hijacking, credential theft, or malware distribution to site visitors.

Technical details

The vulnerability is a stored XSS in the Tabs & Accordions Pro extension where URL parameters are written directly to data-rlta-url attributes without validation of dangerous protocols. The browser code then passes this attribute value to window.open(), executing any embedded JavaScript. The vulnerability bypasses Joomla's content filters because the malicious payload is authored as plugin syntax that appears benign at filter time but becomes executable during rendering; affected versions do not reject javascript: or other executable URL schemes.

Affected products

  • Regular Labs Tabs & Accordions Pro 2.3.0 to 3.1.0

Timeline

  • 2026-09-28: disclosed

References

Related threats