SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2025-15664

MEDIUM · CVSS 6.8 EPSS 0.29%

Source: NVD + CISA KEV + EPSS · Published 2026-09-02 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The Ultimate Before After Image Slider & Gallery plugin for WordPress versions prior to 4.7.19 is vulnerable due to improper escaping of the before-label value, enabling users with Author roles and higher to inject malicious scripts. This could lead to cross-site scripting (XSS) attacks, affecting any user who views the slider, including administrators. WordPress site administrators and security teams should prioritize updating this plugin to mitigate potential exploitation risks.

CVE
CVE-2025-15664
Severity
MEDIUM
CVSS
6.8
EPSS
0.29%
WordPress

Original NVD Description

The Ultimate Before After Image Slider & Gallery WordPress plugin before 4.7.19 does not properly escape the slider's before-label value before its bundled client-side script re-injects it into the DOM, allowing users with the Author role and above to store a payload that executes in the browser of anyone (including an administrator) who views the slider.