Recursos /
Plugins de WordPress /
Beaf Before And After Gallery
SEGURIDAD DE PLUGINS
¿Es seguro Beaf Before And After Gallery?
Need a Before After Image Comparison slider? Create your before and after slider with BEAF. Addon for Elementor Before and After Slider is included.
Qué hace este plugin
- Slug:
beaf-before-and-after-gallery
- Autor: Themefic
- 30000+ instalaciones activas
- 98/100 calificación (106 reseñas en wordpress.org)
- 1107358 descargas totales
- En WordPress.org desde 2020-01-29
before afterbefore after sliderbefore and after sliderbefore-after-elementorelementor before and after slider
Estado de mantenimiento
- Última actualización: 2026-06-22 11:26am GMT
- Probado hasta WordPress: 7.0.2
- Requiere PHP: 7.4+
Vulnerabilidades conocidas
3 CVEs conocidos registrados para Beaf Before And After Gallery.
Reportadas entre 2024 y 2026.
| CVE |
Vulnerabilidad |
Tipo |
Gravedad |
Afectadas |
Corregido en |
Publicado |
Estado |
|
CVE-2025-15665
|
Ultimate Before After Image Slider & Gallery – BEAF [beaf-before-and-after-gallery] < 4.7.1 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Desconocido
|
< 4.7.1
|
4.7.1 |
2026-07-14 |
—
|
|
CVE-2025-47549
|
Ultimate Before After Image Slider & Gallery – BEAF [beaf-before-and-after-gallery] < 4.6.11 |
Carga de archivos sin restricción de tipo peligroso |
Alta
7,2
|
< 4.6.11
|
4.6.11 |
2025-05-07 |
—
|
|
CVE-2024-32433
|
Ultimate Before After Image Slider & Gallery – BEAF [beaf-before-and-after-gallery] < 4.5.5 |
Falsificación de petición en sitios cruzados (CSRF) |
Media
4,3
|
< 4.5.5
|
4.5.5 |
2024-04-12 |
—
|
CVE-2025-15665
The Ultimate Before After Image Slider & Gallery WordPress plugin before 4.7.1 does not escape the value of the BEAF Slider widget's shortcode field before outputting it on the front end (the value is passed through do_shortcode, which echoes non-shortcode content verbatim), allowing users with administrator-level access to store a script that executes in the browser of any visitor who loads a page displaying the widget.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2025-47549
The Ultimate Before After Image Slider & Gallery – BEAF plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 4.6.10. This makes it possible for authenticated attackers, with Administrator-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2024-32433
Update the WordPress BEAF plugin to the latest available version (at least 4.5.5).
Dhabaleshwar Das discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress BEAF Plugin. This could allow a malicious actor to force higher privileged users to execute unwanted actions under their current authentication. This vulnerability has been fixed in version 4.5.5.
This vulnerability was reported to and published by Patchstack. Our users receive alerts and protections up to 48 hours in advance.
Have additional information or questions about this entry? Get in touch.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
Cómo solucionarlo
Actualiza este plugin a la última versión de wordpress.org — cada CVE de arriba indica la versión exacta que lo corrigió ("Corregido en") cuando hay una registrada.
Este es el historial completo de vulnerabilidades conocidas del plugin, no un escaneo de una instalación específica — ejecuta un escaneo gratis de tu propio sitio para verificar tu versión instalada exacta.
Alternativas más seguras / más establecidas
Verifica tu propio sitio WordPress
Ejecuta un escaneo pasivo gratis ahora, o crea una cuenta gratuita e instala el plugin de WP Clinic para un escaneo profundo de toda tu cuenta de hosting y reparación asistida por IA.