PatchSiren cyber security CVE debrief
CVE-2025-15664 Ultimate Before After Image Slider & Gallery CVE debrief
The Ultimate Before After Image Slider & Gallery WordPress plugin before 4.7.19 does not properly escape the slider's before-label value before its bundled client-side script re-injects it into the DOM, allowing users with the Author role and above to store a payload that executes in the browser of anyone (including an administrator) who views the slider.
- Vendor
- Ultimate Before After Image Slider & Gallery
- Product
- Ultimate Before After Image Slider & Gallery
- CVSS
- MEDIUM 6.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-02
- Original CVE updated
- 2026-09-03
- Advisory published
- 2026-09-02
- Advisory updated
- 2026-09-03
Who should care
Administrators and users of the Ultimate Before After Image Slider & Gallery WordPress plugin, as well as security teams and vulnerability management professionals, should be aware of this vulnerability and take necessary defensive actions to prevent exploitation. This includes reviewing and updating affected product deployments, restricting access to plugin settings, and monitoring for suspicious activity. Vulnerability management professionals should prioritize this vulnerability due to its medium severity and potential for stored XSS attacks.
Technical summary
The Ultimate Before After Image Slider & Gallery WordPress plugin before 4.7.19 does not properly escape the slider's before-label value, allowing users with the Author role and above to store a payload that executes in the browser of anyone who views the slider. The CVSS score is 6.8, indicating a medium severity vulnerability. This vulnerability can be exploited through stored XSS attacks, potentially leading to unauthorized actions or data breaches. Affected product context suggests that users of the Ultimate Before After Image Slider & Gallery WordPress plugin should take necessary defensive actions.
Defensive priority
Medium-priority defensive actions are recommended due to the CVSS score of 6.8 and the potential for stored XSS attacks.
Recommended defensive actions
- Apply the patch or update to version 4.7.19 or later
- Restrict access to the plugin's settings and user roles
- Monitor for suspicious activity and payload injections
- Perform regular security audits and vulnerability assessments
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
Evidence notes
Evidence is based on the NVD vulnerability detail page and a source reference from WPScan. The CVE Program record and NIST NVD detail page provide official vulnerability assessment and metadata. The vulnerability allows users with the Author role and above to store a payload that executes in the browser of anyone who views the slider. Evidence limits suggest that additional details may exist but are not currently verified. Defenders should verify affected product deployments, review official advisories, and plan vendor-supported updates or mitigations.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-15664 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-15664
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-15664 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-15664
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://wpscan.com/vulnerability/31bfd4c6-32e8-4790-b9a8-949fdaba9454/
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.