Back

MEDIUM

BEAF < 4.7.19 - Author+ Stored XSS via Before Label

Published Sep 2, 2026

Description

The Ultimate Before After Image Slider & Gallery WordPress plugin before 4.7.19 does not properly escape the slider's before-label value before its bundled client-side script re-injects it into the DOM, allowing users with the Author role and above to store a payload that executes in the browser of anyone (including an administrator) who views the slider.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner WPScan
Published Sep 2, 2026
Updated Sep 2, 2026
Reserved Jun 23, 2026
CISA Vulnrichment
Updated Sep 2, 2026
NVD
Status Deferred
Modified Sep 3, 2026
Red Hat
Severity n/a
Public date n/a