What is CVE-2026-18988?
CVE-2026-18988 is a Stored Cross-Site Scripting vulnerability in the Easy Accordion plugin for WordPress, affecting versions up to and including 3.1.8. It occurs via the 'accordionTitleTag' block attribute due to insufficient input sanitization and output escaping in the accordion_header_renderer() function. Updating to the latest version is recommended.
Azərbaycanca: CVE-2026-18988, WordPress-in Easy Accordion plagininin 3.1.8-ə qədər versiyalarında 'accordionTitleTag' block atributu vasitəsilə Stored Cross-Site Scripting zəifliyidir. Bu, accordion_header_renderer() funksiyasında kifayət qədər input sanitization və output escaping olmaması səbəbindən yaranır. Plagini ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which WordPress plugin is affected by CVE-2026-18988?
This vulnerability affects the Easy Accordion plugin for WordPress, up to and including version 3.1.8.
What is the root cause of CVE-2026-18988?
The vulnerability occurs due to insufficient input sanitization and output escaping in the accordion_header_renderer() function for the 'accordionTitleTag' block attribute.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.