Impact
The Ultimate Before After Image Slider & Gallery plugin fails to escape content supplied to the BEAF Slider widget’s shortcode before rendering, enabling an administrator or user with back‑office editing privileges to embed JavaScript that will execute in the browsers of any visitor who loads a page containing the widget. The vulnerability arises because the plugin passes raw, non‑shortcode content through do_shortcode, which echoes it verbatim, creating an input unfiltered condition. This allows a privileged user to store a script that runs client‑side for all site visitors seeing the widget.
Affected Systems
All installations of the Ultimate Before After Image Slider & Gallery WordPress plugin with a version earlier than 4.7.1 are at risk. No specific version sub‑break‑points are provided; any release in the 4.x series before the 4.7.1 release contains the flaw.
Risk and Exploitability
Moderate risk overall, as the vulnerability requires privileged back‑office access but once in place delivers client‑side code to all page visitors. The CVSS score of 5.4 indicates moderate severity, and the low EPSS score of < 1% suggests that active exploitation is presently uncommon. Yet, the potential for broad user impact makes prompt action advisable.
OpenCVE Enrichment