Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2025-15665— BEAF < 4.7.1 - Admin+ Stored XSS via Widget Shortcode Field

Quick assessment

Affected
Unknown Ultimate Before After Image Slider & Gallery
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

themefic ultimate before after image slider & gallery是themefic个人开发者开源的一个图片对比插件。 WordPress Ultimate Before After Image Slider & Gallery 4.7.1之前版本存在跨站脚本漏洞,该漏洞源于未对BEAF Slider部件短代码字段的值进行转义,允许具有管理员级别访问权限的用户存储脚本。

AI Predicted 6.1 Difficulty: Easy EPSS 0.23% · P12

Affected Version Matrix 1

VendorProduct Version RangeStatus
Unknown Ultimate Before After Image Slider & Gallery < 4.7.1 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2025-15665

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
BEAF < 4.7.1 - Admin+ Stored XSS via Widget Shortcode Field
Source: CVE Program / CVE List V5
Vulnerability Description
The Ultimate Before After Image Slider & Gallery WordPress plugin before 4.7.1 does not escape the value of the BEAF Slider widget's shortcode field before outputting it on the front end (the value is passed through do_shortcode, which echoes non-shortcode content verbatim), allowing users with administrator-level access to store a script that executes in the browser of any visitor who loads a page displaying the widget.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
WordPress Ultimate Before After Image Slider & Gallery 跨站脚本漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
themefic ultimate before after image slider & gallery是themefic个人开发者开源的一个图片对比插件。 WordPress Ultimate Before After Image Slider & Gallery 4.7.1之前版本存在跨站脚本漏洞,该漏洞源于未对BEAF Slider部件短代码字段的值进行转义,允许具有管理员级别访问权限的用户存储脚本。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Unknown Ultimate Before After Image Slider & Gallery 0 ~ 4.7.1 -

II. Public POCs for CVE-2025-15665

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2025-15665

请登录查看更多情报信息。

News Coverage for CVE-2025-15665 (1)

Same Patch Batch · Unknown · 2026-07-14 · 6 CVEs total

CVE-2026-12583 Newsletters < 4.15 - Unauthenticated PHP Object Injection via Subscriber Custom Field
CVE-2026-12988 WP 2FA < 3.1.1.2 - Account Takeover via 2FA Setup Email Binding
CVE-2026-11563 Word Count and Social Shares <= 1.0 - Subscriber+ Arbitrary File Deletion via Path Travers
CVE-2026-11567 SureForms < 2.11.1 - Unauthenticated Payment Amount Bypass
CVE-2026-12511 AI Engine < 3.5.5 - Editor+ Arbitrary File Write via Path Traversal

IV. Related Vulnerabilities

V. Comments for CVE-2025-15665

No comments yet


Leave a comment