Impact
The vulnerability arises because the plugin fails to escape the value entered in the slider’s after‑label field before it is re‑inserted into the page by the bundled JavaScript. An attacker who can create or edit a slider with the Author role or higher can store a malicious JavaScript payload that will run in the browsers of any visitor who views that slider, including site administrators. This stored cross‑site scripting can lead to session hijacking, credential theft, or arbitrary code execution within the context of the site.
Affected Systems
The issue affects installations of the WordPress plugin Ultimate Before After Image Slider & Gallery version 4.7.18 and earlier. Deployments of any site that uses the plugin before the announced 4.7.19 release are vulnerable. The vendor is listed as Unknown in the CVE data, but the plugin is widely available from the WordPress plugin repository.
Risk and Exploitability
Although no EPSS score is available and the vulnerability is not listed in CISA’s KEV catalog, the risk is typical of stored XSS flaws that execute in arbitrary user browsers. Attackers need only the ability to create or edit a slider, a privilege usually granted to users with Author or higher roles. Anyone who views the impacted slider will have the injected script executed, so the risk window covers all visitors, including administrators. Because the flaw is client‑side and does not require network reconnaissance, the exploit is likely to be discovered and leveraged promptly once a site is discovered to host the vulnerable plugin.
OpenCVE Enrichment