Sceawere
Vulnerability Detail
CVE-2026-92767UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Stored XSS in Twenty20 Image
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.4
- Creation Date
- 2h ago
- Vendor
- zayedbaloch
- Product
- Twenty20 Image Before-After
- Attack Type
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
The Twenty20 Image Before-After plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'offset' Shortcode Attribute in all versions up to, and including, 2.0.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.4",
"pubDate": "2026-10-03T08:16:27.163Z",
"pubdate": "2026-10-03T08:16:27.163Z",
"executiveSummary": "The Twenty20 Image Before-After WordPress plugin contains a Stored Cross-Site Scripting (XSS) vulnerability affecting all versions up to and including 2.0.5.\nThe vulnerability arises from the application's failure to adequately sanitize the 'offset' attribute within the plugin's shortcode functionality.\nBy injecting malicious JavaScript into this attribute, an authenticated attacker with contributor-level privileges or higher can execute arbitrary scripts within the context of a victim's browser session.\nThis vulnerability poses a significant security risk, as successful exploitation allows for unauthorized actions, session hijacking, credential theft, or redirection to malicious sites when a user views the compromised page.\nThe attack is persistent; once the payload is stored on the server, it executes every time a user views the affected page, without requiring further interaction from the attacker.",
"technicalDetails": "The root cause of this vulnerability is improper input validation and output encoding in the handling of the 'offset' attribute within the shortcode parsing logic of the Twenty20 Image Before-After plugin.\nThe application accepts user-supplied data for the 'offset' parameter without performing necessary sanitization to strip or escape potentially malicious characters or script tags.\nWhen this shortcode is rendered on a page, the unsanitized value is directly embedded into the HTML output. If an attacker inputs JavaScript into this attribute, the browser will interpret and execute the script because the application fails to utilize appropriate output encoding methods.\nThe attack flow follows a structured path: First, an authenticated attacker (Contributor or higher) creates or modifies a post/page and inserts the Twenty20 shortcode. Second, the attacker injects the malicious payload into the 'offset' attribute, for example, by setting it to a value like [twenty20 offset='<script>alert(document.cookie)</script>'].\nThird, once the post is saved, the malicious payload is stored in the WordPress database.\nFinally, when any authenticated or unauthenticated user views the page containing the shortcode, the plugin processes the shortcode, fails to escape the 'offset' attribute, and renders the JavaScript directly into the HTML source code. The victim's browser then executes the attacker's script.\nBecause the payload is persistent, this results in a classic Stored XSS attack. The impact is significant because the script runs with the victim's privileges within the application's domain, potentially allowing an attacker to perform actions as the victim, bypass CSRF protections, or exfiltrate sensitive session information.\nThis vulnerability is limited to WordPress installations running Twenty20 Image Before-After versions 2.0.5 and below, requiring the attacker to have, at minimum, contributor-level access to the target WordPress environment."
}