themefic ultimate before after image slider & gallery是themefic个人开发者开源的一个图片对比插件。 WordPress Ultimate Before After Image Slider & Gallery 4.7.1之前版本存在跨站脚本漏洞,该漏洞源于未对BEAF Slider部件短代码字段的值进行转义,允许具有管理员级别访问权限的用户存储脚本。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Unknown | Ultimate Before After Image Slider & Gallery | < 4.7.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | Ultimate Before After Image Slider & Gallery | 0 ~ 4.7.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-12583 | Newsletters < 4.15 - Unauthenticated PHP Object Injection via Subscriber Custom Field | |
| CVE-2026-12988 | WP 2FA < 3.1.1.2 - Account Takeover via 2FA Setup Email Binding | |
| CVE-2026-11563 | Word Count and Social Shares <= 1.0 - Subscriber+ Arbitrary File Deletion via Path Travers | |
| CVE-2026-11567 | SureForms < 2.11.1 - Unauthenticated Payment Amount Bypass | |
| CVE-2026-12511 | AI Engine < 3.5.5 - Editor+ Arbitrary File Write via Path Traversal |
No comments yet