What the vulnerability does
01Description
Subscriber Cross Site Scripting (XSS) in Accordion <= 3.0.6 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
What the vulnerability does
Subscriber Cross Site Scripting (XSS) in Accordion <= 3.0.6 versions.
Explanation of Vulnerability in Simple Terms
Themepoints Accordion versions up to 3.0.6 contain a cross-site scripting (XSS) vulnerability that allows authenticated users to inject malicious scripts. An attacker with low-level site access can craft a malicious accordion configuration that executes JavaScript in other users' browsers when they view the affected page. The vulnerability requires user interaction and can affect other site components.
What an attacker can do
Inject JavaScript code that runs in other users' browsers when they view an accordion.
Potential impact on your site
Authenticated attackers can steal session cookies, deface content, or redirect visitors to malicious sites.
Conditions required to exploit
Attacker needs low-level site access (e.g., contributor role) and the victim must view a page with the malicious accordion.
Key dates
External resources
Related vulnerabilities