Browse all 5 CVE security advisories affecting joedolson. AI-powered Chinese analysis, POCs, and references for each vulnerability.
Joedolson develops WordPress accessibility plugins, primarily serving website owners needing compliance solutions. Historically, vulnerabilities have included stored cross-site scripting (XSS), arbitrary file inclusion, and insufficient input validation leading to remote code execution. Notable incidents include CVE-2021-24732, which allowed unauthenticated attackers to execute arbitrary PHP code via crafted requests, and CVE-2021-24733, enabling privilege escalation through improper capability checks. These vulnerabilities often stem from inadequate sanitization of user-supplied data and improper implementation of WordPress security mechanisms. The plugin's core functionality frequently interacts with sensitive WordPress functions, increasing potential attack surface when security controls are misconfigured or bypassed.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-2362 | WP Accessibility <= 2.3.1 - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via 'alt' Attribute — WP AccessibilityCWE-79 | 6.4 | Medium | 2026-02-27 |
This page lists every published CVE security advisory associated with joedolson. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.