Hello,
We would like to report a vulnerability identified in the Accordions WordPress plugin, discovered by security researcher Ananda Dhakal (Patchstack).
You can access the original report here: https://patchstack.com/database/report-preview/f5c1e7bf-ba17-4a50-aa6e-77c6dc6a47bd/preview, using the following PIN code: 8Fj2k5Px7U01W2A2.
Please note that Patchstack operates as a research-focused CNA and runs a Bug Bounty Program https://patchstack.com/bug-bounty/ for independent security researchers. We do not request any reward and are sharing this information to support timely remediation. As part of our disclosure policy, the vulnerability will be disclosed 30 days after reporting.
Once a patch is ready, please submit it for validation via the report page. To receive status updates, you can connect your plugin to the free Patchstack mVDP program - https://patchstack.com/for-plugins/ or provide an email address through the communication preferences form on the report page.
For general guidance on addressing vulnerabilities, you may find this resource helpful: https://patchstack.com/articles/common-plugin-vulnerabilities-how-to-fix-them/
If you have any questions about this report or our services, please feel free to contact us at triage@patchstack.com.
Thank you, and have a great day.
