WP Vulnerability WatchVulnerability data as of September 7, 2026

Known vulnerabilities in Ultimate FAQ Accordion Plugin

Full-featured FAQ and accordion plugin with advanced search, simple UI and easy-to-use FAQ blocks and shortcodes.

6Reported vulnerabilities
7.5Highest CVSS score
2.4.13Latest version
30,000+Active installs

What to do now

Update Ultimate FAQ Accordion Plugin to 2.4.8 or later. 6 of these have a fixed version available. Updating resolves them.

Plugin last updated: July 29, 2026 / Tested up to WordPress: 7.0.4 / View on wordpress.org

Reported vulnerabilities

Ordered by how urgently they need attention — whether a vulnerability is actually being exploited, and how likely exploitation is, rather than CVSS severity alone.

CVESeverityExploit probability
next 30 days
Affected versionsFixed inPublished
CVE-2019-17232 High 7.5 3.5% 1.8.24 and earlier 1.8.25 October 7, 2019
CVE-2019-17233 Medium 6.1 1.8% 1.8.24 and earlier 1.8.25 October 7, 2019
CVE-2020-7107 Medium 6.1 2.2% Before 1.8.30 1.8.30 January 16, 2020
CVE-2026-4336 Medium 6.4 0.2% 0 to 2.4.7 (inclusive) 2.4.8 April 9, 2026
CVE-2019-15643 Medium 6.1 0.9% Before 1.8.22 1.8.22 August 27, 2019
CVE-2025-67590 Medium 4.3 0.1% 2.4.3 and earlier 2.4.4 November 8, 2025

Sources: vulnerability records from NVD, exploitation from CISA KEV, exploit probability from EPSS. Affected versions come from CPE ranges or from the reporting CNA.