Stored Cross-Site Scripting in Twenty20 Image Before-After Plugin for WordPress
CVE-2026-92767
6.4MEDIUM
What is CVE-2026-92767?
The Twenty20 Image Before-After plugin for WordPress allows authenticated users with contributor access and above to exploit a stored cross-site scripting vulnerability through the 'offset' shortcode attribute. Due to inadequate input sanitization and output escaping, attackers can inject malicious scripts into web pages. This poses a significant security risk as any user accessing the compromised page may unknowingly execute the injected scripts, leading to potential data breaches or site manipulation.
Affected Version(s)
Twenty20 Image Before-After 0 <= 2.0.5