Executive brief
A vulnerability in the Easy Accordion WordPress plugin allows users with contributor-level access or higher to inject malicious scripts into website pages. This occurs through the plugin's FAQ and accordion block features. If exploited, these scripts will run automatically whenever a visitor views the affected page, potentially leading to unauthorized actions or data theft.
Technical details
The Easy Accordion plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping on the 'align' block attribute within the ShortcodeBlock.php component. An authenticated attacker with contributor-level permissions or higher can inject arbitrary web scripts into the block attributes. These scripts are stored on the server and execute in the context of a user's browser whenever they visit the compromised page. The vulnerability affects all versions up to and including 3.1.6.
Affected products
- shapedplugin Easy Accordion – AI-Powered FAQ & Accordion Blocks, Product FAQ up to, and including, 3.1.6
Timeline
- 2026-07-16: disclosed: Vulnerability published by Wordfence and NVD
References
- https://plugins.trac.wordpress.org/browser/easy-accordion-free/tags/3.1.5/Blocks/Includes/ShortcodeBlock.php
- https://plugins.trac.wordpress.org/browser/easy-accordion-free/tags/3.1.5/Blocks/Includes/ShortcodeBlock.php
- https://plugins.trac.wordpress.org/browser/easy-accordion-free/tags/3.1.5/Blocks/Includes/ShortcodeBlock.php
- https://plugins.trac.wordpress.org/changeset?reponame=&old=3607006%40easy-accordion-free&new=3607006%40easy-accordion-free
- https://www.wordfence.com/threat-intel/vulnerabilities/id/eb0fb0a7-b9f7-42db-b826-fc09090bd817?source=cve