Impact
The vulnerability is an unauthenticated Cross Site Scripting flaw in the WordPress plugin 'Before After Image Comparison – Image comparison for WP', affecting all versions 1.1.21 and earlier. An attacker can inject malicious JavaScript that is executed within the browser context of any user that visits a page containing the vulnerable plugin. This could allow the attacker to steal session cookies, perform phishing, or load additional malicious content. The weakness corresponds to CWE-79, which indicates that input is not properly sanitized before being displayed.
Affected Systems
This flaw impacts installations of the 'Before After Image Comparison – Image comparison for WP' plugin from vendor bPlugins. The affected versions are all releases up to and including 1.1.21. WordPress sites that rely on this plugin for image comparison functionality are at risk until the plugin is updated or removed. No additional information is available about operating systems or server configurations.
Risk and Exploitability
The CVSS base score of 7.1 classifies the flaw as High severity, but the EPSS score is not available, so the current probability of exploitation is unclear. The flaw is not listed in CISA’s KEV catalog, suggesting no widespread exploitation yet. An attacker could exploit the flaw by simply visiting a page that loads the vulnerable plugin, making the attack vector unauthenticated and publicly accessible. The impact is limited to the victim’s browser, but the potential for social engineering and data theft is significant.
OpenCVE Enrichment