WPIntell

Source evidence

Plugin has vulnerability issues

Twenty20 Image Before-After · support · 2024-01-03T08:36:00+00:00

mixedsentiment
highseverity
0.95relevance
3replies
Evidence linked to opportunitycommercial context

Proof Health

Open evidence

Commercial opportunities need traceable source links before they are treated as build-worthy.

3 / 32 rows with source links

9.4% of this page's analysis has direct source links.

0 build-decision rows missing links

0 rows here require auditable proof before promotion.

29 rows with no attached evidence

0 rows have source counts but still need direct links.

Conversation

support
bishawjit-das resolved
The plugin does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks https://wpscan.com/vulnerability/e54804c7-68a9-4c4c-94f9-1c3c9b97e8ca/ This is shocking it’s a vulnerability a year old and obviously it would be very easy to validate and fix. So I guess that this developer is no longer around. Is there any other alternative plugin that can do this job @mayy3321 I faced the same problem and ended up replacing this plugin with a similar one called Ultimate Before After Image Slider & Gallery – BEAF. https://wordpress.org/plugins/beaf-before-and-after-gallery/ Although the free version is limited, I was able to replicate my before/after sliders and create a two-column gallery. Here’s a demo of this plugin: https://themefic.com/plugins/beaf/ Hope that helps! Hi everyone, I sincerely apologize for the oversight regarding the security vulnerabilities in the plugin. We take your concerns very seriously. The issues with the shortcode attributes and potential Stored Cross-Site Scripting attacks have been addressed. The plugin has been fully reviewed by the WordPress plugin team, and the latest version 1.7.1 is now available. I strongly encourage you to update the plugin to ensure your sites remain secure. Thank you for your patience and understanding. Best regards,

Comments

3 shown
mayy3321 2024-05-24T07:26:00+00:00

This is shocking it’s a vulnerability a year old and obviously it would be very easy to validate and fix. So I guess that this developer is no longer around. Is there any other alternative plugin that can do this job

Kondor with a K 2024-06-04T21:51:00+00:00

@mayy3321 I faced the same problem and ended up replacing this plugin with a similar one called Ultimate Before After Image Slider & Gallery – BEAF. https://wordpress.org/plugins/beaf-before-and-after-gallery/ Although the free version is limited, I was able to replicate my before/after sliders and create a two-column gallery. Here’s a demo of this plugin: https://themefic.com/plugins/beaf/ Hope that helps!

Zayed Baloch 2024-07-02T16:46:00+00:00

Hi everyone, I sincerely apologize for the oversight regarding the security vulnerabilities in the plugin. We take your concerns very seriously. The issues with the shortcode attributes and potential Stored Cross-Site Scripting attacks have been addressed. The plugin has been fully reviewed by the WordPress plugin team, and the latest version 1.7.1 is now available. I strongly encourage you to update the plugin to ensure your sites remain secure. Thank you for your patience and understanding. Best regards,