Impact
The Twenty20 Image Before‑After plugin permits stored XSS when the `offset` shortcode attribute is used. Input sanitization is insufficient and output is not escaped, allowing a malicious contributor or higher to embed javascript that executes for any user who views the affected page. This flaw can lead to session hijacking, credential theft, defacement or other client‑side compromise.
Affected Systems
WordPress sites running the zayedbaloch Twenty20 Image Before‑After plugin version 2.0.5 or earlier are affected. Versions after 2.0.5 contain the fix and are not vulnerable.
Risk and Exploitability
The CVSS score of 6.4 indicates a moderate severity flaw. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog. The flaw requires an authenticated user with contributor‑level or higher privileges. As a result, attackers can only exploit it from within the site’s user management system. The impact is confined to the attacker’s ability to execute arbitrary scripts in the context of other site visitors, though a successful exploit does not provide direct server‑side access.
OpenCVE Enrichment