Accordion
This hub aggregates every CVE we track for Accordion, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.
9
CVEs tracked
0
Critical
1
High
0
In CISA KEV
Severity distribution
MEDIUM8HIGH1
Monthly trend
0
1
0
0
0
0
0
1
0
0
0
0
1
1
0
0
1
0
0
0
0
0
0
0
2024-092026-08
Latest CVEs
The 9 most recently published vulnerabilities affecting Accordion.
- CVE-2025-69350WordPress Accordion plugin <= 3.0.3 - Cross Site Scripting (XSS) vulnerability5.9
- CVE-2025-53421WordPress Accordion plugin <= 2.3.14 - Broken Access Control vulnerability6.5
- CVE-2025-58678WordPress Accordion Plugin <= 2.3.15 - Broken Access Control Vulnerability6.5
- CVE-2025-32143WordPress Accordion plugin <= 2.3.11 - PHP Object Injection vulnerability8.8
- CVE-2024-47342WordPress Accordion plugin <= 2.2.99 - Cross Site Scripting (XSS) vulnerability6.5
- CVE-2023-47809WordPress Accordion Plugin <= 2.6 is vulnerable to Cross Site Scripting (XSS)5.9
- CVE-2023-5666Accordion <= 2.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode6.4
- CVE-2021-24283Accordion < 2.2.30 - Authenticated Reflected Cross-Site Scripting (XSS)5.4
- CVE-2020-13644An issue was discovered in the Accordion plugin before 2.2.9 for WordPress. The unprotected AJAX wp_ajax_accordions_ajax_import_json action allowed any authenticated user with Subscriber or higher ...5.4
Product normalization is registry-driven with AI assist and human review. How it works