S4E just found a high top 10 tcp port service scan
critical·Product Based Web Vulnerabilities·Updated Dec 1, 2025

CVE-2022-33198 Scanner

CVE-2022-33198 Scanner - Unauthenticated Settings Update vulnerability in WordPress Accordions Plugin

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
3.1k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-33198
5.3
CVSScritical
Exploitable remotely over the internet · no authentication required.

Unauthenticated WordPress Options Change vulnerability in Biplob Adhikari's Accordions plugin <= 2.0.2 at WordPress.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Accordions (WordPress plugin)by Biplob Adhikari
<= 2.0.2
Updated Aug 22, 2026View on NVD →
Detail

The WordPress Accordions plugin is a widely used tool for website owners looking to create collapsible sections on their websites. Often utilized for FAQs or organized content display, it is popular among bloggers, companies, and those maintaining WordPress sites that prioritize content presentation. As a WordPress plugin developed by Biplob Adhikari, it's commonly integrated into sites running the WordPress framework. Users benefit from dynamic content display options, enhancing user interaction. As a result, the plugin contributes to improved site aesthetics and user experience.

The vulnerability in question allows for the unauthorized manipulation of settings within the WordPress Accordions plugin. Exploiting this vulnerability, attackers can change the plugin options without authentication, thereby exposing sites to significant risk. The critical nature of this flaw stems from issues in authentication checks, allowing malicious actors the potential to interfere with site configurations. The vulnerability particularly affects versions up to and including 2.0.2 of the plugin. Given the nature of this flaw, sites running this plugin version are urged to address the issue promptly.

Technically, this vulnerability involves improper authorization within the plugin, specifically at the endpoint '/wp-json/oxiaccordionsultimate/v1/oxi_settings'. Attackers utilize this endpoint to alter settings by crafting specific payloads. Typically, the attack is executed through HTTP requests containing manipulated data, exploiting gaps in the plugin's access control. The parameter 'rawdata' within these requests becomes a key vector for attackers, enabling them to inject new settings values. The lack of sufficient input validation and authentication checks makes this endpoint particularly susceptible to such manipulations.

The exploitation of this vulnerability could lead to various adverse effects, including site defacement, disruption of functionality, or even further exploitation of the site. Attackers can alter critical settings, which may result in unexpected behavior or exposed sensitive information. Furthermore, they can potentially extend their control over the site, leading to a compromised infrastructure. In severe cases, this can lead to loss of trust among users and stakeholders owing to the extent of the breach.

REFERENCES

Solution Advice
  • Update to the latest version of the Accordions plugin where the issue is fixed.
  • Ensure strong authentication checks are in place for settings update endpoints.
  • Regularly audit and monitor plugin configurations for unauthorized changes.
  • Apply security plugins or measures that enhance WordPress site protection.
  • Conduct regular vulnerability assessments on WordPress installations and plugins.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2022-33198 Scanner - Unauthenticated Settings Update vulnerability in WordPress Accordions Plugin S4E