# CVE-2025-15663

## Summary

- **CVE ID:** CVE-2025-15663
- **Severity:** MEDIUM
- **CVSS Score:** 6.8 (CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H)
- **CWE:** N/A
- **Published:** Sep 2, 2026
- **Last Modified:** Sep 2, 2026

## Description

The Ultimate Before After Image Slider & Gallery  WordPress plugin before 4.7.19 does not properly escape the slider's after-label value before its bundled client-side script re-injects it into the DOM, allowing users with the Author role and above to store a payload that executes in the browser of anyone (including an administrator) who views the slider.

## Affected Products

- Unknown — Ultimate Before After Image Slider & Gallery (0)

## References

- [CNA](https://wpscan.com/vulnerability/56dd063a-c097-4fed-83bc-99799b4a229d/)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.29%
- **EPSS Percentile:** 21.7

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-17._