Vulnerabilities and security researches forwp-photo-album-plus wp-photo-album-plus
Direction: ascendingJun 07, 2024
WP Photo Album Plus # CVE-2013-3254
- CVE, Research URL
- Home page URL
- Application
- Date
- May 10, 2013
- Research Description
- Cross-site scripting (XSS) vulnerability in wp-admin/admin.php in the WP Photo Album Plus plugin before 5.0.3 for WordPress allows remote attackers to inject arbitrary web script or HTML via the commentid parameter in a wppa_manage_comments edit action.
- Affected versions
-
max 5.0.3.
- Status
-
vulnerable
WP Photo Album Plus # CVE-2021-25115
- CVE, Research URL
- Home page URL
- Application
- Date
- Feb 14, 2022
- Research Description
- The WP Photo Album Plus WordPress plugin before 8.0.10 was vulnerable to Stored Cross-Site Scripting (XSS). Error log content was handled improperly, therefore any user, even unauthenticated, could cause arbitrary javascript to be executed in the admin panel.
- Affected versions
-
max 8.0.10.
- Status
-
vulnerable
WP Photo Album Plus # CVE-2015-3647
- CVE, Research URL
- Home page URL
- Application
- Date
- May 22, 2015
- Research Description
- Multiple cross-site scripting (XSS) vulnerabilities in wppa-ajax-front.php in the WP Photo Album Plus (aka WPPA) plugin before 6.1.3 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) comemail or (2) comname parameter in a wppa do-comment action.
- Affected versions
-
max 6.1.3.
- Status
-
vulnerable
WP Photo Album Plus # CVE-2023-49813
- CVE, Research URL
- Home page URL
- Application
- Date
- Dec 14, 2023
- Research Description
- Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in J.N. Breetvelt a.K.A. OpaJaap WP Photo Album Plus allows Stored XSS.This issue affects WP Photo Album Plus: from n/a through 8.5.02.005.
- Affected versions
-
max 8.6.01.005.
- Status
-
vulnerable
WP Photo Album Plus # CVE-2023-49774
- CVE, Research URL
- Home page URL
- Application
- Date
- Jun 04, 2024
- Research Description
- Exposure of Sensitive Information to an Unauthorized Actor vulnerability in J.N. Breetvelt a.K.A. OpaJaap WP Photo Album Plus allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WP Photo Album Plus: from n/a through 8.5.02.005.
- Affected versions
-
max 8.6.01.005.
- Status
-
vulnerable
WP Photo Album Plus # CVE-2024-4037
- CVE, Research URL
- Home page URL
- Application
- Date
- May 24, 2024
- Research Description
- The WP Photo Album Plus plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 8.7.02.003. This is due to the plugin allowing unauthenticated users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.
- Affected versions
-
max 8.7.00.004.
- Status
-
vulnerable
WP Photo Album Plus # CVE-2024-31286
- CVE, Research URL
- Home page URL
- Application
- Date
- Apr 07, 2024
- Research Description
- Unrestricted Upload of File with Dangerous Type vulnerability in J.N. Breetvelt a.K.A. OpaJaap WP Photo Album Plus.This issue affects WP Photo Album Plus: from n/a before 8.6.03.005.
- Affected versions
-
max 8.6.03.005.
- Status
-
vulnerable
WP Photo Album Plus # CVE-2024-31377
- CVE, Research URL
- Home page URL
- Application
- Date
- May 14, 2024
- Research Description
- Unrestricted Upload of File with Dangerous Type vulnerability in J.N. Breetvelt a.K.A. OpaJaap WP Photo Album Plus.This issue affects WP Photo Album Plus: from n/a through 8.7.01.001.
- Affected versions
-
max 8.7.01.002.
- Status
-
vulnerable
WP Photo Album Plus # CVE-2023-49812
- CVE, Research URL
- Home page URL
- Application
- Date
- Dec 20, 2023
- Research Description
- Authorization Bypass Through User-Controlled Key vulnerability in J.N. Breetvelt a.K.A. OpaJaap WP Photo Album Plus.This issue affects WP Photo Album Plus: from n/a through 8.5.02.005.
- Affected versions
-
max 8.6.01.005.
- Status
-
vulnerable
Jun 10, 2024
WP Photo Album Plus # CVE-2014-8814
- CVE, Research URL
- Home page URL
- Application
- Date
- -
- Research Description
- The WP Photo Album Plus plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘walbum’ parameter in versions up to, and including, 5.4.17 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
- Affected versions
-
max 5.4.17.
- Status
-
vulnerable
WP Photo Album Plus # CVE-2008-0939
- CVE, Research URL
- Home page URL
- Application
- Date
- -
- Research Description
- Multiple SQL injection vulnerabilities in wppa.php in the WP Photo Album (WPPA) before 1.1 plugin for WordPress allow remote attackers to execute arbitrary SQL commands via (1) the photo parameter to index.php, used by the wppa_photo_name function; or (2) the album parameter to index.php, used by the wppa_album_name function. NOTE: some of these details are obtained from third party information.
- Affected versions
-
max 1.0.
- Status
-
vulnerable
Jul 02, 2024
WP Photo Album Plus # CVE-2024-37416
- CVE, Research URL
- Home page URL
- Application
- Date
- Jul 22, 2024
- Research Description
- Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in J.N. Breetvelt a.K.A. OpaJaap WP Photo Album Plus allows Reflected XSS.This issue affects WP Photo Album Plus: from n/a through 8.8.00.002.
- Affected versions
-
max 8.8.00.003.
- Status
-
vulnerable
Jul 15, 2024
WP Photo Album Plus # CVE-2024-38713
- CVE, Research URL
- Home page URL
- Application
- Date
- Jul 20, 2024
- Research Description
- Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in J.N. Breetvelt a.K.A. OpaJaap WP Photo Album Plus allows Stored XSS.This issue affects WP Photo Album Plus: from n/a through 8.8.02.002.
- Affected versions
-
max 8.8.02.003.
- Status
-
vulnerable
Oct 18, 2024
WP Photo Album Plus # CVE-2024-9951
- CVE, Research URL
- Home page URL
- Application
- Date
- Oct 17, 2024
- Research Description
- The WP Photo Album Plus plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wppa-tab' parameter in all versions up to, and including, 8.8.05.003 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
- Affected versions
-
max 8.8.07.004.
- Status
-
vulnerable
Nov 10, 2024
WP Photo Album Plus # CVE-2024-10958
- CVE, Research URL
- Home page URL
- Application
- Date
- Nov 10, 2024
- Research Description
- The The WP Photo Album Plus plugin for WordPress is vulnerable to arbitrary shortcode execution via getshortcodedrenderedfenodelay AJAX action in all versions up to, and including, 8.8.08.007 . This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.
- Affected versions
-
max 8.9.01.001.
- Status
-
vulnerable
Nov 10, 2025
WP Photo Album Plus # CVE-2025-8726
- CVE, Research URL
- Home page URL
- Application
- Date
- Oct 04, 2025
- Research Description
- The WP Photo Album Plus plugin for WordPress is vulnerable to Cross-Site Scripting in all versions up to, and including, 9.0.11.006 due to insufficient input sanitization and output escaping in the wppa_user_upload function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts in the photo album descriptions that execute in a victim's browser.
- Affected versions
-
max 9.0.11.007.
- Status
-
vulnerable
Jan 11, 2026
WP Photo Album Plus # CVE-2025-14835
- CVE, Research URL
- Home page URL
- Application
- Date
- Jan 07, 2026
- Research Description
- The WP Photo Album Plus plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘shortcode’ parameter in all versions up to, and including, 9.1.05.008 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
- Affected versions
-
max 9.1.05.009.
- Status
-
vulnerable
Apr 24, 2026
WP Photo Album Plus # CVE-2026-39511
- CVE, Research URL
- Home page URL
- Application
- Date
- Jun 16, 2026
- Research Description
- Unauthenticated SQL Injection in WP Photo Album Plus <= 9.1.08.001 versions.
- Affected versions
-
max 9.1.08.002.
- Status
-
vulnerable
May 20, 2026
WP Photo Album Plus # CVE-2026-6379
- CVE, Research URL
- Home page URL
- Application
- Date
- May 18, 2026
- Research Description
- The WP Photo Album Plus WordPress plugin before 9.1.11.001 does not properly sanitize and escape a parameter before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks.
- Affected versions
-
max 9.1.11.001.
- Status
-
vulnerable
Jun 16, 2026
WP Photo Album Plus # db114a6cc3ed913fafaf0fec6606e454374e54fd
- CVE, Research URL
- Home page URL
- Application
- Date
- May 15, 2015
- Research Description
- WP Photo Album Plus [wp-photo-album-plus] < 4.8.12 WordPress WP Photo Album Plus Plugin <= 4.8.11 - XSS This plugin is prone to wp-photo-album-plus.php wppa-searchstring cross site scripting vulnerability Update the plugin.
- Affected versions
-
max 4.8.12.
- Status
-
vulnerable
WP Photo Album Plus # 60a217d11704d0619509744d04379bd49df588d9
- CVE, Research URL
- Home page URL
- Application
- Date
- Jun 19, 2016
- Research Description
- WP Photo Album Plus [wp-photo-album-plus] < 5.4.5 WordPress WP Photo Album Plus Plugin <= 5.4.4 - Cross Site Scripting This plugin is prone to a cross site scripting vulnerability. Update the plugin.
- Affected versions
-
max 5.4.5.
- Status
-
vulnerable
WP Photo Album Plus # 3754cfbd13b78cc3dbdae21bc2f7b8e0a2e85c61
- CVE, Research URL
- Home page URL
- Application
- Date
- May 15, 2015
- Research Description
- WP Photo Album Plus [wp-photo-album-plus] < 5.0.11 WordPress WP Photo Album Plus Plugin <= 5.0.10 - XSS This plugin is prone to wp-admin/admin.php edit_id parameter cross site scripting vulnerability. Update the plugin.
- Affected versions
-
max 5.0.11.
- Status
-
vulnerable
WP Photo Album Plus # 11a6e9ded1432ac3927c200d193aebb845d109b9
- CVE, Research URL
- Home page URL
- Application
- Date
- May 15, 2015
- Research Description
- WP Photo Album Plus [wp-photo-album-plus] < 5.4.18 WordPress WP Photo Album Plus Plugin <= 5.4.17 Reflected XSS Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code. Update the plugin.
- Affected versions
-
max 5.4.18.
- Status
-
vulnerable
WP Photo Album Plus # 822f2c3b-2b5b-40a8-b18b-47de228caf30
- CVE, Research URL
- Home page URL
- Application
- Date
- -
- Research Description
- WP Photo Album Plus [wp-photo-album-plus] < 4.9.1 WP Photo Album Plus - Full Path Disclosure The WP Photo Album Plus WordPress plugin was affected by a Full Path Disclosure security vulnerability.
- Affected versions
-
max 4.9.1.
- Status
-
vulnerable
WP Photo Album Plus # eb2ff4cf218ffe6232da4e38aebd77844497d7a4
- CVE, Research URL
- Home page URL
- Application
- Date
- May 15, 2015
- Research Description
- WP Photo Album Plus [wp-photo-album-plus] < 4.9.3 WordPress WP Photo Album Plus Plugin <= 4.9.2 - XSS This plugin is prone to index.php wppa-tag parameter cross site scripting vulnerability. Update the plugin.
- Affected versions
-
max 4.9.3.
- Status
-
vulnerable
WP Photo Album Plus # 7aa775aed713ae615ab608d4d7cabe33df0e3a3a
- CVE, Research URL
- Home page URL
- Application
- Date
- May 15, 2015
- Research Description
- WP Photo Album Plus [wp-photo-album-plus] < 5.4.9 WordPress WP Photo Album Plus Plugin <= 5.4.8 - Stored XSS This plugin is prone to a stored cross site scripting vulnerability. Update the plugin.
- Affected versions
-
max 5.4.9.
- Status
-
vulnerable
WP Photo Album Plus # 0870d4ecb90d9a5be79d1a28205fbf2762e7e054
- CVE, Research URL
- Home page URL
- Application
- Date
- Oct 15, 2011
- Research Description
- WP Photo Album Plus [wp-photo-album-plus] < 4.1.2 WordPress Photo Album Plus Plugin <= 4.1.1 - SQL Injection WPPhoto Album Plus plugin is prone to an SQL injection. This vulnerability allows an attacker to modify data, alter queries to the application SQL database, compromise the access and application or exploit hidden vulnerabilities in the underlying database. Update the plugin.
- Affected versions
-
max 4.1.2.
- Status
-
vulnerable
WP Photo Album Plus # cc03812f-c60e-4c83-a8f5-e4567a96d65c
- CVE, Research URL
- Home page URL
- Application
- Date
- -
- Research Description
- WP Photo Album Plus [wp-photo-album-plus] < 5.4.8 WP Photo Album Plus 5.4.5 - 5.4.8 Stored XSS The WP Photo Album Plus WordPress plugin was affected by a 5.4.8 Stored XSS security vulnerability.
- Affected versions
-
max 5.4.8.
- Status
-
vulnerable
WP Photo Album Plus # ca9da69344d5721ca2a97f6eaeb76a0e8c6fddfe
- CVE, Research URL
- Home page URL
- Application
- Date
- Oct 18, 2015
- Research Description
- WP Photo Album Plus [wp-photo-album-plus] < 4.9.1 WordPress WP Photo Album Plus Plugin <= 4.9.0 - Full Path Disclosure This plugin is prone to a full path disclosure vulnerability. Update the plugin.
- Affected versions
-
max 4.9.1.
- Status
-
vulnerable
WP Photo Album Plus # 63232980-9bb5-48fa-b9ce-1076dd52c6d5
- CVE, Research URL
- Home page URL
- Application
- Date
- -
- Research Description
- WP Photo Album Plus [wp-photo-album-plus] < 5.0.11 WP Photo Album Plus - wp-admin/admin.php edit_id Parameter XSS The WP Photo Album Plus WordPress plugin was affected by a wp-admin/admin.php edit_id Parameter XSS security vulnerability.
- Affected versions
-
max 5.0.11.
- Status
-
vulnerable
WP Photo Album Plus # 3072681f-7aa6-45ef-91c2-02cb981dff54
- CVE, Research URL
- Home page URL
- Application
- Date
- -
- Research Description
- WP Photo Album Plus [wp-photo-album-plus] < 5.4.5 WP Photo Album Plus 5.4.4 & 5.4.3 Cross-Site Scripting (XSS) The WP Photo Album Plus WordPress plugin was affected by security vulnerability.
- Affected versions
-
max 5.4.5.
- Status
-
vulnerable
WP Photo Album Plus # 1693cffd-e578-4091-84bf-cb151281ca8e
- CVE, Research URL
- Home page URL
- Application
- Date
- -
- Research Description
- WP Photo Album Plus [wp-photo-album-plus] < 4.2.0 WP Photo Album Plus <= 4.1.1 - SQL Injection The WP Photo Album Plus WordPress plugin was affected by a SQL Injection security vulnerability.
- Affected versions
-
max 4.2.0.
- Status
-
vulnerable
WP Photo Album Plus # cf2ec17f-cc0f-4918-9614-ab3bcfa8cf58
- CVE, Research URL
- Home page URL
- Application
- Date
- -
- Research Description
- WP Photo Album Plus [wp-photo-album-plus] < 4.8.12 WP Photo Album Plus < 4.8.12 - wp-photo-album-plus.php wppa-searchstring XSS The WP Photo Album Plus WordPress plugin was affected by a wp-photo-album-plus.php wppa-searchstring XSS security vulnerability.
- Affected versions
-
max 4.8.12.
- Status
-
vulnerable
WP Photo Album Plus # f7b99fd4f8e9b751948a0b385e19119256d8ce92
- CVE, Research URL
- Home page URL
- Application
- Date
- Sep 17, 2014
- Research Description
- WP Photo Album Plus [wp-photo-album-plus] >= 5.4.5 - <= 5.4.8 WP Photo Album Plus <= 5.4.7 - Stored Cross-Site Scripting The WP Photo Album Plus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'zip' parameter in versions up to, and including, 5.4.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
- Affected versions
-
Min 5.4.5, max 5.4.8.
- Status
-
vulnerable
WP Photo Album Plus # 76534e35-3b2c-493a-b589-4ce98b8ca553
- CVE, Research URL
- Home page URL
- Application
- Date
- -
- Research Description
- WP Photo Album Plus [wp-photo-album-plus] < 4.9.3 WP Photo Album Plus - index.php wppa-tag Parameter XSS The WP Photo Album Plus WordPress plugin was affected by an index.php wppa-tag Parameter XSS security vulnerability.
- Affected versions
-
max 4.9.3.
- Status
-
vulnerable
Jun 25, 2026
WP Photo Album Plus # CVE-2026-54829
- CVE, Research URL
- Home page URL
- Application
- Date
- -
- Research Description
- WP Photo Album Plus [wp-photo-album-plus] < 9.2.01.001 CVE-2026-54829
- Affected versions
-
max 9.2.01.001.
- Status
-
vulnerable
Jul 02, 2026
WP Photo Album Plus # CVE-2026-10095
- CVE, Research URL
- Home page URL
- Application
- Date
- Jul 01, 2026
- Research Description
- The WP Photo Album Plus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'subtext' parameter in all versions up to, and including, 9.1.13.005 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. A contributor-level attacker can embed the malicious [photo] shortcode in a post submitted for review, causing the stored payload to execute when an administrator or any other user views the post.
- Affected versions
-
max 9.2.01.001.
- Status
-
vulnerable
Jul 30, 2026
WP Photo Album Plus # CVE-2026-15344
- CVE, Research URL
- Home page URL
- Application
- Date
- Jul 29, 2026
- Research Description
- The WP Photo Album Plus plugin for WordPress is vulnerable to generic SQL Injection via the 'table' parameter in all versions up to, and including, 9.2.04.002 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. The export-table endpoint lacks a nonce check, meaning this vulnerability can also be triggered via CSRF by tricking an authenticated administrator into visiting a malicious page.
- Affected versions
-
max 9.2.04.003.
- Status
-
vulnerable
Aug 02, 2026
WP Photo Album Plus # CVE-2026-14922
- CVE, Research URL
- Home page URL
- Application
- Date
- Jul 31, 2026
- Research Description
- WP Photo Album Plus is vulnerable to stored Cross-Site Scripting in all versions up to, and including, 9.2.03.001 through a decode-after-sanitize (double-encoding) flaw in the photo-comment pipeline. On write, `wppa_do_comment()` sanitizes the comment with `wppa_filter_html()` (wp_kses) followed by `wp_strip_all_tags()` (`wppa-functions.php:2623-2624`). Because `wp_strip_all_tags()` only removes *real* tags, an attacker who submits a **double HTML-entity-encoded** payload (e.g. `&lt;img src=... onload=...&gt;`) passes the write filters as harmless entity text and is stored one decode-level down (`<img ... onload=...>`).
- Affected versions
-
max 9.2.04.003.
- Status
-
vulnerable
Aug 11, 2026
WP Photo Album Plus # CVE-2026-17014
- CVE, Research URL
- Home page URL
- Application
- Date
- Aug 09, 2026
- Research Description
- The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not perform any capability or nonce check on one of its public REST endpoint actions, allowing unauthenticated users to delete the generated album export ZIP archives it stores.
- Affected versions
-
max 9.2.07.002.
- Status
-
vulnerable
Aug 14, 2026
WP Photo Album Plus # CVE-2026-18962
- CVE, Research URL
- Home page URL
- Application
- Date
- Aug 12, 2026
- Research Description
- The WP Photo Album Plus WordPress plugin before 9.2.09.002 does not check that the current user is allowed to upload into the album they target when it processes a front-end upload, allowing any authenticated user, such as a Subscriber, to upload files into albums owned by other users or by the administrator. Exploitation requires the WP Photo Album Plus WordPress plugin before 9.2.09.002's front-end user upload feature to be enabled, which is not the default.
- Affected versions
-
max 9.2.09.002.
- Status
-
vulnerable
WP Photo Album Plus # CVE-2026-17013
- CVE, Research URL
- Home page URL
- Application
- Date
- Aug 12, 2026
- Research Description
- The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not sanitise and escape a parameter before reflecting it into an inline script block, which could allow unauthenticated attackers to perform Reflected Cross-Site Scripting attacks against anyone who is tricked into opening a crafted link to a page displaying one of its galleries.
- Affected versions
-
max 9.2.07.002.
- Status
-
vulnerable
WP Photo Album Plus # CVE-2026-18049
- CVE, Research URL
- Home page URL
- Application
- Date
- Aug 12, 2026
- Research Description
- The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not perform any capability or nonce check on one of its public endpoint actions and builds an option name from a client-supplied value without restricting it to its own options, allowing unauthenticated users to read the value of other autoloaded options whose names end in a matching suffix.
- Affected versions
-
max 9.2.07.002.
- Status
-
vulnerable
WP Photo Album Plus # CVE-2026-18048
- CVE, Research URL
- Home page URL
- Application
- Date
- Aug 12, 2026
- Research Description
- The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not validate a client-controlled value used to build a file path in one of its public endpoint actions, and performs no authorisation check on it, allowing unauthenticated attackers to delete arbitrary ZIP archives on the server, including ones stored outside the web root.
- Affected versions
-
max 9.2.07.002.
- Status
-
vulnerable
Sep 11, 2026
WP Photo Album Plus # CVE-2026-18579
- CVE, Research URL
- Home page URL
- Application
- Date
- Sep 11, 2026
- Research Description
- The WP Photo Album Plus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'HTTP_X_FORWARDED_FOR' parameter in all versions up to, and including, 9.2.08.003 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The nonce failure path for the getshortcodedrenderedfenodelay action serves as the log-write trigger rather than an access barrier — a deliberately failed nonce check causes wppa_log() to record the attacker-supplied X-Forwarded-For value to disk, making the exploit fully reachable by unauthenticated callers via the wp_ajax_nopriv_wppa endpoint.
- Affected versions
-
max 9.2.10.001.
- Status
-
vulnerable
Sep 20, 2026
WP Photo Album Plus # CVE-2026-87909
- CVE, Research URL
- Home page URL
- Application
- Date
- Sep 19, 2026
- Research Description
- The WP Photo Album Plus plugin for WordPress is vulnerable to Remote Code Execution in all versions via the wppa_image_magick function. This is due to insufficient sanitization of the multipart upload filename before concatenation into an ImageMagick command string executed via exec(), with only escapeshellcmd() applied to the whole command rather than quoting individual arguments. This makes it possible for authenticated attackers, with subscriber-level access and above, to execute code on the server. escapeshellcmd() escapes shell metacharacters but does not prevent argument injection because spaces remain as argument separators, and the filename sanitization applied at the database layer is never applied to the physical temporary file path used for ImageMagick processing.
- Affected versions
-
max 9.3.01.003.
- Status
-
vulnerable
Sep 25, 2026
WP Photo Album Plus # CVE-2026-93774
- CVE, Research URL
- Home page URL
- Application
- Date
- Sep 24, 2026
- Research Description
- Unauthenticated Cross Site Scripting (XSS) in WP Photo Album Plus <= 9.3.02.002 versions.
- Affected versions
-
max 9.3.02.003.
- Status
-
vulnerable
Oct 07, 2026
WP Photo Album Plus # CVE-2026-102386
- CVE, Research URL
- Home page URL
- Application
- Date
- Sep 30, 2026
- Research Description
- Subscriber Cross Site Scripting (XSS) in WP Photo Album Plus <= 9.3.02.003 versions.
- Affected versions
-
max 9.3.03.002.
- Status
-
vulnerable