First published: Thu May 28 2020(Updated: )
An issue was discovered in the Accordion plugin before 2.2.9 for WordPress. The unprotected AJAX wp_ajax_accordions_ajax_import_json action allowed any authenticated user with Subscriber or higher permissions the ability to import a new accordion and inject malicious JavaScript as part of the accordion.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
PickPlugins Accordion | <2.2.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2020-13644.
The severity of CVE-2020-13644 is medium with a CVSS score of 5.4.
The affected software of CVE-2020-13644 is the Accordion plugin before version 2.2.9 for WordPress.
An authenticated user with Subscriber or higher permissions can exploit CVE-2020-13644 by using the unprotected AJAX wp_ajax_accordions_ajax_import_json action to import a new accordion and inject malicious JavaScript.
CVE-2020-13644 can be fixed by updating the Accordion plugin to version 2.2.9 or higher.