Impact
The Ultimate Before After Image Slider & Gallery WordPress plugin has a stored cross‑site scripting flaw. The slider’s before‑label value is inserted into the page by bundled JavaScript without proper escaping. A user with the Author role or higher can save a malicious payload in this field, which is then rendered in the browsers of anyone who views the slider. The vulnerability allows arbitrary client‑side code execution but does not provide direct server‑side access or data theft beyond the victim’s browser context.
Affected Systems
This problem affects WordPress sites that have the Ultimate Before After Image Slider & Gallery plugin installed with a version earlier than 4.7.19. Any site that permits a user with the Author role or higher to edit the slider’s before‑label is vulnerable. No other vendors or products are listed, and the plugin is the sole affected component.
Risk and Exploitability
Exploitation requires a legitimate account with Author or higher privileges to add or edit slider content. Once the payload is saved, every user who loads the slider will execute the code in their browser. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. However, because the flaw can be injected by users who already have edit rights and because the attack path is straightforward, the risk of exploitation is considered high.
OpenCVE Enrichment