CVE Database /
CVE-2025-15665
CVE
CVE-2025-15665 — Ultimate Before After Image Slider & Gallery – BEAF [beaf-before-and-after-gallery] < 4.7.1
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2025-15665
|
Ultimate Before After Image Slider & Gallery – BEAF [beaf-before-and-after-gallery] < 4.7.1 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Unknown
|
< 4.7.1
|
4.7.1 |
2026-06-23 |
—
|
CVE-2025-15665
The BEAF WordPress plugin contains a security flaw that allows malicious users with elevated privileges to insert unauthorized code into certain pages, which can then be executed by other users when those pages are accessed. This vulnerability arises from inadequate handling of user input and output in the affected versions up to 4.7.0. The issue specifically affects multi-site WordPress installations or sites where HTML filtering is enabled.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings