Description
The Ultimate Before After Image Slider & Gallery WordPress plugin before 4.7.1 does not escape the value of the BEAF Slider widget's shortcode field before outputting it on the front end (the value is passed through do_shortcode, which echoes non-shortcode content verbatim), allowing users with administrator-level access to store a script that executes in the browser of any visitor who loads a page displaying the widget.
Published: 2026-07-14
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Ultimate Before After Image Slider & Gallery plugin fails to escape content supplied to the BEAF Slider widget’s shortcode before rendering, enabling an administrator or user with back‑office editing privileges to embed JavaScript that will execute in the browsers of any visitor who loads a page containing the widget. The vulnerability arises because the plugin passes raw, non‑shortcode content through do_shortcode, which echoes it verbatim, creating an input unfiltered condition. This allows a privileged user to store a script that runs client‑side for all site visitors seeing the widget.

Affected Systems

All installations of the Ultimate Before After Image Slider & Gallery WordPress plugin with a version earlier than 4.7.1 are at risk. No specific version sub‑break‑points are provided; any release in the 4.x series before the 4.7.1 release contains the flaw.

Risk and Exploitability

Moderate risk overall, as the vulnerability requires privileged back‑office access but once in place delivers client‑side code to all page visitors. The CVSS score of 5.4 indicates moderate severity, and the low EPSS score of < 1% suggests that active exploitation is presently uncommon. Yet, the potential for broad user impact makes prompt action advisable.

Generated by OpenCVE AI on August 3, 2026 at 03:32 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Ultimate Before After Image Slider & Gallery plugin to version 4.7.1 or later, which applies the necessary filtering to widget content.
  • If an immediate upgrade is not possible, delete or replace any BEAF Slider widgets that may contain injected scripts, or replace them with a plain image shortcode or a secured gallery configuration.
  • After applying the fix, implement a Content Security Policy that disallows inline scripts and restricts script origins to mitigate future injection attempts.

Generated by OpenCVE AI on August 3, 2026 at 03:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 03 Aug 2026 04:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79

Fri, 31 Jul 2026 11:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79

Wed, 29 Jul 2026 06:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79

Thu, 23 Jul 2026 03:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79

Mon, 20 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79

Thu, 16 Jul 2026 08:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79

Tue, 14 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Ultimate Before After Image Slider & Gallery WordPress plugin before 4.7.1 does not escape the value of the BEAF Slider widget's shortcode field before outputting it on the front end (the value is passed through do_shortcode, which echoes non-shortcode content verbatim), allowing users with administrator-level access to store a script that executes in the browser of any visitor who loads a page displaying the widget.
Title BEAF < 4.7.1 - Admin+ Stored XSS via Widget Shortcode Field
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-07-14T12:47:58.589Z

Reserved: 2026-06-23T11:11:48.893Z

Link: CVE-2025-15665

cve-icon Vulnrichment

Updated: 2026-07-14T12:47:54.677Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T03:45:05Z

Weaknesses

No weakness.