๐Ÿ” CVE Alert

CVE-2025-15664

UNKNOWN 0.0

BEAF < 4.7.19 - Author+ Stored XSS via Before Label

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Ultimate Before After Image Slider & Gallery WordPress plugin before 4.7.19 does not properly escape the slider's before-label value before its bundled client-side script re-injects it into the DOM, allowing users with the Author role and above to store a payload that executes in the browser of anyone (including an administrator) who views the slider.

Vendor unknown
Product ultimate before after image slider & gallery
Published Sep 2, 2026
Stay Ahead of the Next One

Get instant alerts for unknown ultimate before after image slider & gallery

Be the first to know when new unknown vulnerabilities affecting unknown ultimate before after image slider & gallery are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Ultimate Before After Image Slider & Gallery
0 < 4.7.19

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/31bfd4c6-32e8-4790-b9a8-949fdaba9454/

Credits

Dmitrii Ignatyev WPScan