Junglewise Threat Intelligence

CVE-2026-15652: ShapedPlugin Easy Accordion Stored XSS in align Block Attribute

CVE-2026-15652 · Severity: medium · CVSS 6.4 · Published 2026-07-16

Executive brief

A vulnerability in the Easy Accordion WordPress plugin allows users with contributor-level access or higher to inject malicious scripts into website pages. This occurs through the plugin's FAQ and accordion block features. If exploited, these scripts will run automatically whenever a visitor views the affected page, potentially leading to unauthorized actions or data theft.

Technical details

The Easy Accordion plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping on the 'align' block attribute within the ShortcodeBlock.php component. An authenticated attacker with contributor-level permissions or higher can inject arbitrary web scripts into the block attributes. These scripts are stored on the server and execute in the context of a user's browser whenever they visit the compromised page. The vulnerability affects all versions up to and including 3.1.6.

Affected products

  • shapedplugin Easy Accordion – AI-Powered FAQ & Accordion Blocks, Product FAQ up to, and including, 3.1.6

Timeline

  • 2026-07-16: disclosed: Vulnerability published by Wordfence and NVD

References