CyberRota Analysis
AI-GeneratedThe Ultimate Before After Image Slider & Gallery plugin for WordPress versions prior to 4.7.19 is vulnerable due to improper escaping of the slider's after-label value, enabling users with the Author role and higher to inject malicious scripts. This could lead to cross-site scripting (XSS) attacks, affecting any user who views the slider, including administrators. WordPress site administrators and developers should prioritize updating this plugin to mitigate potential exploitation.
Original NVD Description
The Ultimate Before After Image Slider & Gallery WordPress plugin before 4.7.19 does not properly escape the slider's after-label value before its bundled client-side script re-injects it into the DOM, allowing users with the Author role and above to store a payload that executes in the browser of anyone (including an administrator) who views the slider.