CVE-2025-66092: WordPress Accordion Slider plugin <= 1.9.13 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bqworks Accordion Slider accordion-slider allows Stored XSS.This issue affects Accordion Slider: from n/a through <= 1.9.13.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-66092?
CVE-2025-66092 is categorized as a high severity vulnerability due to its potential for Stored Cross-site Scripting (XSS).
How do I fix CVE-2025-66092?
To fix CVE-2025-66092, update the bqworks Accordion Slider plugin to version 1.9.14 or later that addresses the vulnerability.
Who is affected by CVE-2025-66092?
CVE-2025-66092 affects users of bqworks Accordion Slider and WordPress Accordion Slider versions up to and including 1.9.13.
What type of vulnerability is CVE-2025-66092?
CVE-2025-66092 is classified as a Cross-site Scripting (XSS) vulnerability that allows attackers to inject malicious scripts.
What attributes of input are not properly neutralized in CVE-2025-66092?
CVE-2025-66092 involves improper neutralization of input during web page generation, enabling Stored XSS attacks.