WP Clinic
Log in Sign up

PLUGIN SECURITY

Is Beaf Before And After Gallery safe?

Known vulnerabilities, PHP compatibility and safer alternatives for the Beaf Before And After Gallery WordPress plugin — checked against WP Clinic's local security database.

What this plugin does

  • Slug: beaf-before-and-after-gallery

Maintenance status

Known vulnerabilities

3 known CVEs on file for Beaf Before And After Gallery. Reported between 2024 and 2026.

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-15665 Ultimate Before After Image Slider & Gallery – BEAF [beaf-before-and-after-gallery] < 4.7.1 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Unknown < 4.7.1 4.7.1 2026-07-14
CVE-2025-47549 Ultimate Before After Image Slider & Gallery – BEAF [beaf-before-and-after-gallery] < 4.6.11 Unrestricted Upload of File with Dangerous Type High 7.2 < 4.6.11 4.6.11 2025-05-07
CVE-2024-32433 Ultimate Before After Image Slider & Gallery – BEAF [beaf-before-and-after-gallery] < 4.5.5 Cross-Site Request Forgery (CSRF) Medium 4.3 < 4.5.5 4.5.5 2024-04-12

CVE-2025-15665

The Ultimate Before After Image Slider & Gallery WordPress plugin before 4.7.1 does not escape the value of the BEAF Slider widget's shortcode field before outputting it on the front end (the value is passed through do_shortcode, which echoes non-shortcode content verbatim), allowing users with administrator-level access to store a script that executes in the browser of any visitor who loads a page displaying the widget.

Source: CVE.org

CVE-2025-47549

The Ultimate Before After Image Slider & Gallery – BEAF plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 4.6.10. This makes it possible for authenticated attackers, with Administrator-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.

Source: Wordfence

CVE-2024-32433

Update the WordPress BEAF plugin to the latest available version (at least 4.5.5). Dhabaleshwar Das discovered and reported this Cross Site Request Forgery (CSRF) vulnerability in WordPress BEAF Plugin. This could allow a malicious actor to force higher privileged users to execute unwanted actions under their current authentication. This vulnerability has been fixed in version 4.5.5. This vulnerability was reported to and published by Patchstack. Our users receive alerts and protections up to 48 hours in advance. Have additional information or questions about this entry? Get in touch.

Source: Patchstack

How to fix it

Update this plugin to the latest release from wordpress.org — each CVE above lists the exact release that fixed it ("Fixed in") when one is on file.

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.