CVE

CVE-2025-15665 — Ultimate Before After Image Slider & Gallery – BEAF [beaf-before-and-after-gallery] < 4.7.1

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-15665 Ultimate Before After Image Slider & Gallery – BEAF [beaf-before-and-after-gallery] < 4.7.1 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Unknown < 4.7.1 4.7.1 2026-06-23

CVE-2025-15665

The BEAF WordPress plugin contains a security flaw that allows malicious users with elevated privileges to insert unauthorized code into certain pages, which can then be executed by other users when those pages are accessed. This vulnerability arises from inadequate handling of user input and output in the affected versions up to 4.7.0. The issue specifically affects multi-site WordPress installations or sites where HTML filtering is enabled.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.