CVE-2025-49066: WordPress Accordion Slider PRO plugin <= 1.2 - Reflected Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup Accordion Slider PRO accordionsliderpro allows Reflected XSS.This issue affects Accordion Slider PRO: from n/a through <= 1.2.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-49066?
CVE-2025-49066 has been classified as a medium severity vulnerability due to its potential for reflected cross-site scripting (XSS).
How do I fix CVE-2025-49066?
To fix CVE-2025-49066, update the Accordion Slider PRO plugin to the latest version that resolves this XSS vulnerability.
What type of vulnerability is CVE-2025-49066?
CVE-2025-49066 is a reflected cross-site scripting (XSS) vulnerability that allows attackers to inject malicious scripts into web pages.
Which software versions are affected by CVE-2025-49066?
CVE-2025-49066 affects all versions of the Accordion Slider PRO plugin up to and including version 1.2.
Who is the vendor for CVE-2025-49066?
The vendor for CVE-2025-49066 is LambertGroup, responsible for the Accordion Slider PRO plugin.