CVE WATCH / VULNERABILITY DETAIL
CVE-2026-92767
MEDIUMCVSS 6.4NVD feed
Published 3 October 2026 · tracked since 3 October 2026
Description
The Twenty20 Image Before-After plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'offset' Shortcode Attribute in all versions up to, and including, 2.0.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contribu
References
- NVD — National Vulnerability Database
- CVE.org record (MITRE)
- CISA Known Exploited Vulnerabilities catalog
Latest tracked vulnerabilities
- CVE-2026-105118 MEDIUM 4.7
- CVE-2026-97873
- CVE-2026-71889
- CVE-2026-71891
- CVE-2026-71885
- CVE-2026-71886
- CVE-2026-92084 CRITICAL 9.1
- CVE-2026-94505 HIGH 8.1
- CVE-2026-96267 HIGH 7.5
- CVE-2026-97343 MEDIUM 4.3