WordPress Plugin Vulnerabilities

BEAF < 4.7.19 - Author+ Stored XSS via Before Label

Description

The plugin does not properly escape the slider's before-label value before its bundled client-side script re-injects it into the DOM, allowing users with the Author role and above to store a payload that executes in the browser of anyone (including an administrator) who views the slider.

Proof of Concept

Affects Plugins

References

Classification

Type
XSS
CWE

Miscellaneous

Original Researcher
Dmitrii Ignatyev
Submitter
Dmitrii Ignatyev
Verified
Yes

Timeline

Publicly Published
2026-08-31 (about 2 days ago)
Added
2026-08-31 (about 1 day ago)
Last Updated
2026-08-31 (about 1 day ago)

Other