PLUGIN SECURITY

Is Web Accessibility - WCAG Scanning, Guided Fixes, Usability Widget safe?

Web Accessibility (formally known as Ally) is a free, powerful, and user-friendly plugin that helps WordPress creators build more accessible websites …

What this plugin does

  • Slug: pojo-accessibility
  • Author: Elementor
  • 500000+ active installs
  • 58/100 rating (162 reviews on wordpress.org)
  • 5903211 all-time downloads
  • On WordPress.org since 2015-10-29

a11yaccessibilityAccessibility statementwcagweb accessibility

Maintenance status

  • Latest known version: 4.1.3
  • Last updated: 2026-08-24 11:04am GMT
  • Tested up to WordPress: 7.0.4
  • Requires PHP: 7.4+
  • Max supported PHP (analyzed): 8.4

Known vulnerabilities

4 known CVEs on file for Web Accessibility - WCAG Scanning, Guided Fixes, Usability Widget.

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-25386 Web Accessibility (formally known as Ally) – WCAG Scanning, Guided Fixes, Usability Widget [pojo-accessibility] < 4.0.3 Missing Authorization Medium 5.3 < 4.0.3 4.0.3 2026-02-19 ✓ fixed in latest
CVE-2025-10700 Web Accessibility (formally known as Ally) – WCAG Scanning, Guided Fixes, Usability Widget [pojo-accessibility] < 3.8.1 Cross-Site Request Forgery (CSRF) Medium 4.3 < 3.8.1 3.8.1 2025-10-15 ✓ fixed in latest
CVE-2025-32640 Web Accessibility (formally known as Ally) – WCAG Scanning, Guided Fixes, Usability Widget [pojo-accessibility] < 3.2.0 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.9 < 3.2.0 3.2.0 2025-04-09 ✓ fixed in latest
Web Accessibility (formally known as Ally) – WCAG Scanning, Guided Fixes, Usability Widget [pojo-accessibility] < 4.1.0 Unknown < 4.1.0 4.1.0 0000-00-00 ✓ fixed in latest
CVE-2026-2413 Ally < 4.1.0 - Unauthenticated SQLi via URL Path Unknown < 4.1.0 4.1.0 ✓ fixed in latest

How to fix it

Keep Web Accessibility - WCAG Scanning, Guided Fixes, Usability Widget updated — 4.1.3 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Safer / more established alternatives

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.