Cross-Site Scripting in Ultimate Before After Image Slider & Gallery by WordPress
CVE-2025-15664

Currently unrated

Key Information:

Vendor

WordPress

Vendor
CVE Published:
2 September 2026

Badges

๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC

What is CVE-2025-15664?

The Ultimate Before After Image Slider & Gallery for WordPress lacks proper escaping of the slider's before-label value. This insufficiency allows users with Author roles and above to inject malicious payloads, which then execute in the browsers of users who view the slider, including administrators. The vulnerability raises significant security concerns, enabling potential exploitation through malicious scripts.

Affected Version(s)

Ultimate Before After Image Slider & Gallery 0 < 4.7.19

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Dmitrii Ignatyev
WPScan
.