Smartwp maintains the Lightweight Accordion WordPress plugin, a niche web component presenting a modest but focused attack surface centered on input-handling in dynamically generated page content. The durable vulnerability signal reflects cross-site scripting risks typical of interactive front-end widgets, where untrusted data flows into the DOM without adequate neutralization. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Smartwp over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-0373MEDIUM The Lightweight Accordion WordPress plugin before 1.5.15 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, | Feb 13, 2023 | 5.4 | 19 | NO | NO |
CVE-2024-2436MEDIUM The Lightweight Accordion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.5.16 due to insuff | Apr 9, 2024 | 5.4 | 17 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Smartwp.
Media articles that mention a CVE ID that affects a product developed by Smartwp — matched by CVE ID, not by vendor name.