
š Easy Accordion WordPress plugin hit by stored XSS CVE-2026-18988 ā CVSS 6.4 Easy Accordion through 3.1.8 contains a stored XSS flaw that can allow Contributor-level users to inject scripts into affected pages. š Published: August 8. š Source: Rapid7 / CVE. #WordPress #XSS #CVE #AppSec #CyberSecurity
Post summary
CVE-2026-18988 is a stored XSS vulnerability in the Easy Accordion WordPress plugin that allows Contributor-level users to inject scripts, disclosed with a CVSS score of 6.4 on August 8, with no patch, exploit, or active exploitation information provided.
