Plethora Tabs + Accordions
Plethora Tabs + Accordions has 2 disclosed vulnerabilities in the WordSec catalog, all reported in 2025; all 2 are fixed as of September 2026. Their average CVSS score is 6.4, and the most serious one scores 6.4 out of 10. 2025 was the busiest year with 2 disclosures.
The most common weakness is Cross-Site Scripting, behind 1 of the records (50%). Other recurring categories include Doubled Character XSS Manipulations.
Every one of the 2 issues recorded for Plethora Tabs + Accordions has a vendor fix available, so running the current release closes all known holes.
2 independent researchers contributed these findings, one record each. Plethora Tabs + Accordions is installed on roughly 2,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.
CVE-2024-13721Plethora Plugins Tabs + Accordions <= 1.1.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via anchor
Read the full analysisVulnerability Records

Plethora Tabs + Accordions
Author
Plethora Plugins
A user-friendly tabs or accordion block for the default WordPress editor. Designed with accessibility in mind Quickly switch between horizontal/vertical or accordion layout Edit tab labels and content and see the effects immediately in Live Preview. You can select one of the predefined themes (Basic and Tabby) or the Minimal theme that makes it easy to add your own styles. Optimized for the default WordPress themes and the Hello Elementor theme. Some custom CSS styling would likely still be needed in your own implementation; this plugin just provides a lightweight tab/accordion block with minimal styling options. The idea is you would extend this with your own CSS as needed. Visit the Plethora Design site for the documentation! Documentation IMPORTANT: Avoid using tabs with the same labels, or else you will need to override the anchor so that the code can uniquely identify your tab or accordion header. Visit the documentation page for documentation.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C