Description
The Ultimate Before After Image Slider & Gallery WordPress plugin before 4.7.19 does not properly escape the slider's before-label value before its bundled client-side script re-injects it into the DOM, allowing users with the Author role and above to store a payload that executes in the browser of anyone (including an administrator) who views the slider.
Published: 2026-09-02
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Ultimate Before After Image Slider & Gallery WordPress plugin has a stored cross‑site scripting flaw. The slider’s before‑label value is inserted into the page by bundled JavaScript without proper escaping. A user with the Author role or higher can save a malicious payload in this field, which is then rendered in the browsers of anyone who views the slider. The vulnerability allows arbitrary client‑side code execution but does not provide direct server‑side access or data theft beyond the victim’s browser context.

Affected Systems

This problem affects WordPress sites that have the Ultimate Before After Image Slider & Gallery plugin installed with a version earlier than 4.7.19. Any site that permits a user with the Author role or higher to edit the slider’s before‑label is vulnerable. No other vendors or products are listed, and the plugin is the sole affected component.

Risk and Exploitability

Exploitation requires a legitimate account with Author or higher privileges to add or edit slider content. Once the payload is saved, every user who loads the slider will execute the code in their browser. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. However, because the flaw can be injected by users who already have edit rights and because the attack path is straightforward, the risk of exploitation is considered high.

Generated by OpenCVE AI on September 2, 2026 at 07:56 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Ultimate Before After Image Slider & Gallery plugin to version 4.7.19 or later.
  • If an update cannot be performed immediately, remove the plugin from public pages or revoke Author role privileges for all but trusted editors.
  • As a temporary measure, disable the before‑label feature or restrict its use to trusted users, keeping in mind that no official workaround is published.

Generated by OpenCVE AI on September 2, 2026 at 07:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 02 Sep 2026 08:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79

Wed, 02 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Ultimate Before After Image Slider & Gallery WordPress plugin before 4.7.19 does not properly escape the slider's before-label value before its bundled client-side script re-injects it into the DOM, allowing users with the Author role and above to store a payload that executes in the browser of anyone (including an administrator) who views the slider.
Title BEAF < 4.7.19 - Author+ Stored XSS via Before Label
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-02T06:00:16.037Z

Reserved: 2026-06-23T11:04:00.154Z

Link: CVE-2025-15664

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-02T06:17:15.700

Modified: 2026-09-02T06:17:15.700

Link: CVE-2025-15664

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-02T08:00:14Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')