Description
WordPress Plugin Twenty20 Image Before-After contains malicous code. Exploiting this issue may allow an attacker to create a new administrative user account, thus compromising the affected application, and possibly the webserver or computer. WordPress Plugin Twenty20 Image Before-After version 1.6.3 is affected; prior versions may also be affected.
Remediation
Update to plugin version 1.6.4 or latest
References
Related Vulnerabilities
axios Server-Side Request Forgery (SSRF) Vulnerability (CVE-2020-28168)
WordPress Plugin Anti-Malware Security and Brute-Force Firewall Local File Inclusion (4.18.63)
MySQL CVE-2012-0487 Vulnerability (CVE-2012-0487)
WordPress Plugin WP Private Content Plus Cross-Site Request Forgery (3.1)
WordPress Plugin Gmedia Photo Gallery Cross-Site Scripting (0.9.3)