Code Injection Vulnerability in PickPlugins Tabs & Accordion
CVE-2023-40557

5.4MEDIUM

Key Information:

Vendor
WordPress
Vendor
CVE Published:
4 June 2024

Summary

A vulnerability exists in the PickPlugins Tabs & Accordion plugin due to improper handling of script-related HTML tags. This flaw can be exploited for code injection, enabling attackers to introduce malicious scripts into web pages. Attackers can potentially manipulate the content displayed to users, leading to unauthorized actions and data exposure. Users of the Tabs & Accordion plugin, particularly those using versions from n/a up to 1.3.10, should be aware of this risk and take necessary precautions.

Affected Version(s)

Tabs & Accordion <= 1.3.10

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Abdi Pranata (Patchstack Alliance)
.