Bellows Accordion Menu
Bellows Accordion Menu has 2 disclosed vulnerabilities in the WordSec catalog, reported between 2023 and 2025; all 2 are fixed as of September 2026. Their average CVSS score is 6.4, and the most serious one scores 6.4 out of 10.
The most common weakness is Cross-Site Scripting, behind 2 of the records (100%).
Every one of the 2 issues recorded for Bellows Accordion Menu has a vendor fix available, so running the current release closes all known holes.
2 independent researchers contributed these findings, one record each. Bellows Accordion Menu is installed on roughly 10,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.8.8.
CVE-2025-49242Bellows Accordion Menu <= 1.4.3 - Authenticated (Contributor+) Stored Cross-Site Scripting
Read the full analysisVulnerability Records

Bellows Accordion Menu
Author
sevenspark
Bellows is an awesome accordion menu for WordPress. It works with the WordPress menu system to allow you to build beautiful accordion menus for your site. Bellows Lite Demo Bellows Full Demo Get started: Bellows Quick Start Guide Feature Overview Fully functional accordion menu Multiple submenu levels 3 included skin presets Multi- or single-folding Expand current submenu automatically option Shortcode integration – add an accodion menu to yoru site anywhere you can add shortcodes Widget integration – add an accordion menu to your widgetized theme areas
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C