PT-2026-84601 · WordPress · The Ultimate Before After Image Slider & Gallery
CVSS v3.1
6.8
Medium
| Vector | AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
The Ultimate Before After Image Slider & Gallery versions prior to 4.7.19
Description
The plugin fails to properly escape the
after-label value of the slider. This allows users with the Author role or higher to store a malicious payload that is subsequently re-injected into the Document Object Model (DOM) by a bundled client-side script. This can lead to the execution of arbitrary code in the browser of any user, including administrators, who views the affected slider.Recommendations
Update The Ultimate Before After Image Slider & Gallery to version 4.7.19 or later.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
The Ultimate Before After Image Slider & Gallery