WordPress security by component
Ultimate Before After Image Slider & Gallery
Plugin description
Ultimate Before After Image Slider & Gallery creates before-and-after image comparisons using sliders and gallery layouts in WordPress.
Ultimate Before After Image Slider & Gallery (ultimate-before-after-image-slider-gallery) is a WordPress plugin with 4 published CVE records in this archive. The latest tracked vulnerability was published Sep 02, 2026; the highest published CVSS base score is 9.1.
Plugin slug:
ultimate-before-after-image-slider-galleryLatest vulnerability
CVE-2025-15664: Ultimate Before After Image Slider before-label permits stored cross-site scripting
Ultimate Before After Image Slider & Gallery before 4.7.19 does not adequately escape the before-label value before its client-side script reinserts it into the DOM. An Author or higher can store script that executes in the browser of anyone, including an administrator, who views the slider.
Known source slugs: ultimate-before-after-image-slider-&-gallery, ultimate-before-after-image-slider-gallery
| Safe version |
|
||
|---|---|---|---|
| Sep 02, 2026 |
CVE-2025-15664
Ultimate Before After Image Slider before-label permits stored cross-site scripting
Ultimate Before After Image Slider & Gallery before 4.7.19 does not adequately escape the before-label value before its client-side script reinserts it into the DOM. An Author or higher can store script that executes in the browser of anyone, including an administrator, who views the slider.
|
4.7.19 |
CVE6.8
NVDPending
|
| Sep 02, 2026 |
CVE-2025-15663
Ultimate Before After Image Slider after-label permits stored cross-site scripting
Ultimate Before After Image Slider & Gallery before 4.7.19 does not adequately escape the after-label value before its client-side script reinserts it into the DOM. An Author or higher can store script that executes in the browser of anyone, including an administrator, who views the slider.
|
4.7.19 |
CVE6.8
NVDPending
|
| Jul 14, 2026 |
CVE-2025-15665
Ultimate Before After Image Slider & Gallery: A security weakness
Ultimate Before After Image Slider & Gallery is affected by a security weakness. Exploitation requires an authenticated administrator account. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is < 4.7.1.
|
4.7.1 |
CVE5.4
NVDPending
|
| May 07, 2025 |
CVE-2025-47549
BEAF: Dangerous file upload
BEAF is affected by dangerous file upload. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can place attacker-controlled executable content on the server and may lead to full site compromise.
|
See mitigation notes |
CVE9.1
NVD7.2
|