Description
WordPress Plugin Twenty20 Image Before-After contains malicous code. Exploiting this issue may allow an attacker to create a new administrative user account, thus compromising the affected application, and possibly the webserver or computer. WordPress Plugin Twenty20 Image Before-After version 1.6.3 is affected; prior versions may also be affected.
Remediation
Update to plugin version 1.6.4 or latest
References
Related Vulnerabilities
WordPress Plugin Flash Photo Gallery Cross-Site Scripting (0.7)
WordPress Plugin Button Widget Smartsoft Cross-Site Request Forgery (1.0.1)
WordPress Plugin WP Maps-Display Google Maps Perfectly with Ease Unspecified Vulnerability (3.1.6)
MODX Improper Restriction of XML External Entity Reference Vulnerability (CVE-2020-25911)