Cross-Site Scripting in Ultimate Before After Image Slider & Gallery Plugin
CVE-2025-15663

Currently unrated

Key Information:

Vendor

WordPress

Vendor
CVE Published:
2 September 2026

Badges

๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC

What is CVE-2025-15663?

The Ultimate Before After Image Slider & Gallery plugin for WordPress, prior to version 4.7.19, contains a vulnerability where the plugin fails to appropriately escape the slider's after-label value during the re-injection into the DOM. This flaw can be exploited by users with Author roles and above, allowing them to store a malicious payload. Consequently, anyone who views the slider, including administrators, could unknowingly execute this payload in their browser, potentially compromising their session or data. Regular updates and vigilance against such vulnerabilities are crucial for maintaining website security.

Affected Version(s)

Ultimate Before After Image Slider & Gallery 0 < 4.7.19

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Krugov Artyom
WPScan
.