Description
WordPress Plugin Twenty20 Image Before-After contains malicous code. Exploiting this issue may allow an attacker to create a new administrative user account, thus compromising the affected application, and possibly the webserver or computer. WordPress Plugin Twenty20 Image Before-After version 1.6.3 is affected; prior versions may also be affected.
Remediation
Update to plugin version 1.6.4 or latest
References
Related Vulnerabilities
SharePoint CVE-2023-33142 Vulnerability (CVE-2023-33142)
Apache HTTP Server Improper Authentication Vulnerability (CVE-2017-3167)
Atlassian Jira Deserialization of Untrusted Data Vulnerability (CVE-2020-14172)
WordPress Plugin Anti-Malware Security and Brute-Force Firewall Cross-Site Scripting (4.15.22)
WordPress Plugin Quiz and Survey Master (QSM)-Easy Quiz and Survey Maker SQL Injection (9.0.1)