
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-24565 is a Sensitive Data Exposure vulnerability (CWE-201: Insertion of Sensitive Information Into Sent Data) in the B Accordion WordPress plugin by bPlugins. It allows authenticated attackers with at least Contributor-level privileges to retrieve embedded sensitive data that should not be accessible to regular users. The vulnerability affects all versions of B Accordion up to and including 2.0.2, with version 2.0.3 containing the fix. It was reported on December 22, 2025, and publicly disclosed on January 21–23, 2026. The CVSS v3.1 base score is 6.5 (Medium) (Patchstack, NVD).
The vulnerability is classified as CWE-201 (Insertion of Sensitive Information Into Sent Data), meaning the plugin inadvertently includes sensitive data in responses sent to authenticated users who should not have access to it. Exploitation requires a network-accessible WordPress installation and a low-privilege authenticated account (Contributor or Developer level), with no user interaction required. The attack vector is network-based with low complexity, suggesting the sensitive data is exposed through standard plugin functionality — likely via AJAX handlers or REST API endpoints that fail to properly restrict the data returned to lower-privileged users. No public proof-of-concept code has been identified (Patchstack).
Successful exploitation results in a high confidentiality impact with no integrity or availability impact. An authenticated attacker with Contributor-level access could retrieve sensitive information embedded within the plugin's data responses — information that is normally restricted from regular users. This exposed data could potentially be leveraged to facilitate further attacks against the WordPress site or its users, such as privilege escalation or targeted phishing, though direct system compromise is not achievable through this vulnerability alone (Patchstack, NVD).
No public exploit code or active in-the-wild exploitation has been reported for CVE-2026-24565. The EPSS score is approximately 0.018% (0.000180), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Patchstack notes that while vulnerabilities of this class can be used in mass-exploit campaigns targeting WordPress sites, this specific issue is rated low priority and is considered unlikely to be exploited due to the authentication requirement (Patchstack).
/wp-content/plugins/b-accordion/ for plugin presence.wp-admin/admin-ajax.php with B Accordion-related action parameters) from Contributor-level accounts, particularly in rapid succession or from unusual IP addresses.The vendor has released version 2.0.3 of the B Accordion plugin, which resolves this vulnerability. Site administrators should update the plugin immediately via the WordPress admin dashboard or by downloading the patched version from the WordPress plugin repository. As a temporary workaround if immediate updating is not possible, restricting Contributor-level user registration or disabling the B Accordion plugin until patching is feasible can reduce exposure. Patchstack users can enable auto-update for vulnerable plugins to automate remediation (Patchstack).
The vulnerability was discovered and reported by security researcher theviper17 through Patchstack's responsible disclosure process on December 22, 2025. Patchstack classified it as low priority with unlikely exploitation potential. No significant broader media coverage, vendor statements beyond the patch release, or notable community discussion has been identified for this vulnerability.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."