WordPress Plugin Vulnerabilities

BEAF < 4.7.19 - Author+ Stored XSS via After Label

Description

The plugin does not properly escape the slider's after-label value before its bundled client-side script re-injects it into the DOM, allowing users with the Author role and above to store a payload that executes in the browser of anyone (including an administrator) who views the slider.

Proof of Concept

Affects Plugins

References

Classification

Type
XSS
CWE

Miscellaneous

Original Researcher
Krugov Artyom
Submitter
Krugov Aryom
Submitter website
Verified
Yes

Timeline

Publicly Published
2026-08-31 (about 1 day ago)
Added
2026-08-31 (about 19 hours ago)
Last Updated
2026-08-31 (about 19 hours ago)

Other