PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-15664 Ultimate Before After Image Slider & Gallery CVE debrief

The Ultimate Before After Image Slider & Gallery WordPress plugin before 4.7.19 does not properly escape the slider's before-label value before its bundled client-side script re-injects it into the DOM, allowing users with the Author role and above to store a payload that executes in the browser of anyone (including an administrator) who views the slider.

Vendor
Ultimate Before After Image Slider & Gallery
Product
Ultimate Before After Image Slider & Gallery
CVSS
MEDIUM 6.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-02
Original CVE updated
2026-09-03
Advisory published
2026-09-02
Advisory updated
2026-09-03

Who should care

Administrators and users of the Ultimate Before After Image Slider & Gallery WordPress plugin, as well as security teams and vulnerability management professionals, should be aware of this vulnerability and take necessary defensive actions to prevent exploitation. This includes reviewing and updating affected product deployments, restricting access to plugin settings, and monitoring for suspicious activity. Vulnerability management professionals should prioritize this vulnerability due to its medium severity and potential for stored XSS attacks.

Technical summary

The Ultimate Before After Image Slider & Gallery WordPress plugin before 4.7.19 does not properly escape the slider's before-label value, allowing users with the Author role and above to store a payload that executes in the browser of anyone who views the slider. The CVSS score is 6.8, indicating a medium severity vulnerability. This vulnerability can be exploited through stored XSS attacks, potentially leading to unauthorized actions or data breaches. Affected product context suggests that users of the Ultimate Before After Image Slider & Gallery WordPress plugin should take necessary defensive actions.

Defensive priority

Medium-priority defensive actions are recommended due to the CVSS score of 6.8 and the potential for stored XSS attacks.

Recommended defensive actions

  • Apply the patch or update to version 4.7.19 or later
  • Restrict access to the plugin's settings and user roles
  • Monitor for suspicious activity and payload injections
  • Perform regular security audits and vulnerability assessments
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed

Evidence notes

Evidence is based on the NVD vulnerability detail page and a source reference from WPScan. The CVE Program record and NIST NVD detail page provide official vulnerability assessment and metadata. The vulnerability allows users with the Author role and above to store a payload that executes in the browser of anyone who views the slider. Evidence limits suggest that additional details may exist but are not currently verified. Defenders should verify affected product deployments, review official advisories, and plan vendor-supported updates or mitigations.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-15664 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-15664

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-15664 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-15664

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.