Authorization Issue in PickPlugins Accordion Affects WordPress Users
CVE-2025-58678

6.5MEDIUM

Key Information:

Vendor

WordPress

Status
Vendor
CVE Published:
22 September 2025

What is CVE-2025-58678?

A missing authorization vulnerability in PickPlugins Accordion allows attackers to exploit incorrectly configured access control levels. This flaw impacts various versions of the plugin, enabling unauthorized access to features that should be protected. WordPress users with versions ranging from n/a to 2.3.14 are particularly at risk and should take prompt measures to update and secure their installations.

Affected Version(s)

Accordion <= 2.3.14

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Abu Hurayra (Patchstack Alliance)
.