
CVE-2026-1904 The Simple Wp colorfull Accordion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' parameter in the 'accordion' shortcode in all versio… https://www.cve.org/CVERecord?id=CVE-2026-1904
Post summary
CVE-2026-1904 exposes a stored XSS flaw in the Simple WP Colorfull Accordion plugin through the title parameter of the accordion shortcode; no PoC, exploit, or patch information is provided.


