plugin

Wp Photo Album Plus Vulnerabilities

61 known security issues reported for the Wp Photo Album Plus WordPress plugin. Most recent disclosed Aug 14, 2026.

4 critical 8 high 18 medium

Running Wp Photo Album Plus on your site? Check whether your installed version is affected.

Scan your site free

WP Photo Album Plus < 9.2.07.002 - Missing Authorization

medium

The WP Photo Album Plus plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to 9.2.07.002. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 9.2.07.002
Fixed in:
9.2.07.002
Disclosed:
Aug 14, 2026

CVE-2026-18049 on NVD →

WP Photo Album Plus < 9.2.04.003 - Authenticated (Subscriber+) Stored Cross-Site Scripting

medium

The WP Photo Album Plus plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 9.2.04.003 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that wil...

CVSS:
6.4
Affected:
up to 9.2.04.003
Fixed in:
9.2.04.003
Disclosed:
Aug 13, 2026

CVE-2026-14922 on NVD →

Photo Album Plus <= 9.2.07.1 - Arbitrary File Deletion to Unauthenticated Arbitrary ZIP File Deletion

critical

The Photo Album Plus plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 9.2.07.1. This is due to insufficient validation of a user supplied path. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can lead to a site takeover w...

CVSS:
9.1
Affected:
up to 9.2.07.1
Fixed in:
9.2.07.002
Disclosed:
Aug 10, 2026

CVE-2026-18048 on NVD →

Photo Album Plus <= 9.2.07.1 - Reflected Cross-Site Scripting

medium

The Photo Album Plus plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 9.2.07.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successf...

CVSS:
6.1
Affected:
up to 9.2.07.1
Fixed in:
9.2.07.002
Disclosed:
Aug 10, 2026

CVE-2026-17013 on NVD →

Photo Album Plus <= 9.2.09.1 - Missing Authorization

medium

The Photo Album Plus plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 9.2.09.1. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.

CVSS:
4.3
Affected:
up to 9.2.09.1
Fixed in:
9.2.09.002
Disclosed:
Aug 10, 2026

CVE-2026-18962 on NVD →

Photo Album Plus <= 9.2.07.1 - Unauthenticated Export ZIP File Deletion

medium

The Photo Album Plus plugin for WordPress is vulnerable to Arbitrary Zip File Deletion in versions up to, and including, 9.2.07.1. This is due to insufficient validation of a user supplied path. This makes it possible for unauthenticated attackers to delete arbitrary zip files on the server.

CVSS:
5.3
Affected:
up to 9.2.07.1
Fixed in:
9.2.07.002
Disclosed:
Aug 3, 2026

CVE-2026-17014 on NVD →

WP Photo Album Plus <= 9.2.04.002 - Authenticated (Administrator+) SQL Injection via 'table' Parameter

medium

The WP Photo Album Plus plugin for WordPress is vulnerable to generic SQL Injection via the 'table' parameter in all versions up to, and including, 9.2.04.002 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticate...

CVSS:
4.9
Affected:
up to 9.2.04.002
Fixed in:
9.2.04.003
Disclosed:
Jul 28, 2026

CVE-2026-15344 on NVD →

WP Photo Album Plus <= 9.1.13.005 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'subtext' Shortcode Attribute

medium

The WP Photo Album Plus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'subtext' parameter in all versions up to, and including, 9.1.13.005 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above,...

CVSS:
6.4
Affected:
up to 9.1.13.005
Fixed in:
9.2.01.001
Disclosed:
Jun 30, 2026

CVE-2026-10095 on NVD →

WP Photo Album Plus <= 9.2.02.004 - Unauthenticated Stored Cross-Site Scripting

high

The WP Photo Album Plus plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 9.2.02.004 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a us...

CVSS:
7.2
Affected:
up to 9.2.02.004
Fixed in:
9.2.03.001
Disclosed:
Jun 30, 2026

CVE-2026-57675 on NVD →

WP Photo Album Plus <= 9.1.13.005 - Unauthenticated SQL Injection

high

The WP Photo Album Plus plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 9.1.13.005 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL...

CVSS:
7.5
Affected:
up to 9.1.13.005
Fixed in:
9.2.01.001
Disclosed:
Jun 17, 2026

CVE-2026-54829 on NVD →

WP Photo Album Plus < 9.1.11.001 - Unauthenticated SQL Injection

high

The WP Photo Album Plus plugin for WordPress is vulnerable to SQL Injection in versions up to 9.1.11.001 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into al...

CVSS:
7.5
Affected:
up to 9.1.11.001
Fixed in:
9.1.11.001
Disclosed:
Jun 11, 2026

CVE-2026-6379 on NVD →

WP Photo Album Plus <= 9.1.08.001 - Unauthenticated SQL Injection

high

The WP Photo Album Plus plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 9.1.08.001 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL...

CVSS:
7.5
Affected:
up to 9.1.08.001
Fixed in:
9.1.08.002
Disclosed:
Apr 13, 2026

CVE-2026-39511 on NVD →

WP Photo Album Plus [wp-photo-album-plus] < 9.1.05.009

unknown

[en] The WP Photo Album Plus plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘shortcode’ parameter in all versions up to, and including, 9.1.05.008 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web script...

Affected:
up to 9.1.05.009
Fixed in:
9.1.05.009
Disclosed:
Jan 7, 2026

CVE-2025-14835 on NVD →

WP Photo Album Plus <= 9.1.05.008 - Reflected Cross-Site Scripting

high

The WP Photo Album Plus plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘shortcode’ parameter in all versions up to, and including, 9.1.05.008 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in...

CVSS:
7.1
Affected:
up to 9.1.05.008
Fixed in:
9.1.05.009
Disclosed:
Jan 6, 2026

CVE-2025-14835 on NVD →

WP Photo Album Plus <= 9.0.11.006 - Authenticated (Subscriber+) Stored Cross-Site Scripting via wppa_user_upload

medium

The WP Photo Album Plus plugin for WordPress is vulnerable to Cross-Site Scripting in all versions up to, and including, 9.0.11.006 due to insufficient input sanitization and output escaping in the wppa_user_upload function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to...

CVSS:
5.4
Affected:
up to 9.0.11.006
Fixed in:
9.0.11.007
Disclosed:
Oct 3, 2025

CVE-2025-8726 on NVD →

WP Photo Album Plus <= 8.8.08.007 - Unauthenticated Arbitrary Shortcode Execution via getshortcodedrenderedfenodelay

high

The The WP Photo Album Plus plugin for WordPress is vulnerable to arbitrary shortcode execution via getshortcodedrenderedfenodelay AJAX action in all versions up to, and including, 8.8.08.007 . This is due to the software allowing users to execute an action that does not properly validate a value before running do_shor...

CVSS:
7.3
Affected:
up to 8.8.08.007
Fixed in:
8.9.01.001
Disclosed:
Nov 10, 2024

CVE-2024-10958 on NVD →

WP Photo Album Plus [wp-photo-album-plus] < 8.9.01.001

unknown

[en] The The WP Photo Album Plus plugin for WordPress is vulnerable to arbitrary shortcode execution via getshortcodedrenderedfenodelay AJAX action in all versions up to, and including, 8.8.08.007 . This is due to the software allowing users to execute an action that does not properly validate a value before running do...

Affected:
up to 8.9.01.001
Fixed in:
8.9.01.001
Disclosed:
Nov 10, 2024

CVE-2024-10958 on NVD →

WP Photo Album Plus [wp-photo-album-plus] < 8.8.07.004

unknown

[en] The WP Photo Album Plus plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wppa-tab' parameter in all versions up to, and including, 8.8.05.003 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts...

Affected:
up to 8.8.07.004
Fixed in:
8.8.07.004
Disclosed:
Oct 17, 2024

CVE-2024-9951 on NVD →

Wordpress Photo Album Plus <= 8.8.05.003 - Reflected Cross-Site Scripting

medium

The WP Photo Album Plus plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wppa-tab' parameter in all versions up to, and including, 8.8.05.003 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in p...

CVSS:
6.1
Affected:
up to 8.8.05.003
Fixed in:
8.8.07.004
Disclosed:
Oct 16, 2024

CVE-2024-9951 on NVD →

WP Photo Album Plus [wp-photo-album-plus] < 8.8.00.003

unknown

[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in J.N. Breetvelt a.K.A. OpaJaap WP Photo Album Plus allows Reflected XSS.This issue affects WP Photo Album Plus: from n/a through 8.8.00.002.

Affected:
up to 8.8.00.003
Fixed in:
8.8.00.003
Disclosed:
Jul 22, 2024

CVE-2024-37416 on NVD →

WP Photo Album Plus [wp-photo-album-plus] < 8.8.02.003

unknown

[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in J.N. Breetvelt a.K.A. OpaJaap WP Photo Album Plus allows Stored XSS.This issue affects WP Photo Album Plus: from n/a through 8.8.02.002.

Affected:
up to 8.8.02.003
Fixed in:
8.8.02.003
Disclosed:
Jul 20, 2024

CVE-2024-38713 on NVD →

WP Photo Album Plus <= 8.8.02.002 - Authenticated (Subscriber+) Stored Cross-Site Scripting

medium

The WP Photo Album Plus plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 8.8.02.002 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts i...

CVSS:
6.4
Affected:
up to 8.8.02.002
Fixed in:
8.8.02.003
Disclosed:
Jul 11, 2024

CVE-2024-38713 on NVD →

WP Photo Album Plus <= 8.8.00.002 - Reflected Cross-Site Scripting

medium

The WP Photo Album Plus plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 8.8.00.002 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can suc...

CVSS:
6.1
Affected:
up to 8.8.00.002
Fixed in:
8.8.00.003
Disclosed:
Jun 28, 2024

CVE-2024-37416 on NVD →

WP Photo Album Plus [wp-photo-album-plus] < 8.6.01.005

unknown

[en] Exposure of Sensitive Information to an Unauthorized Actor vulnerability in J.N. Breetvelt a.K.A. OpaJaap WP Photo Album Plus allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WP Photo Album Plus: from n/a through 8.5.02.005.

Affected:
up to 8.6.01.005
Fixed in:
8.6.01.005
Disclosed:
Jun 4, 2024

CVE-2023-49774 on NVD →

WP Photo Album Plus [wp-photo-album-plus] < 8.7.00.004

unknown

[en] The WP Photo Album Plus plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 8.7.02.003. This is due to the plugin allowing unauthenticated users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for...

Affected:
up to 8.7.00.004
Fixed in:
8.7.00.004
Disclosed:
May 24, 2024

CVE-2024-4037 on NVD →

WP Photo Album Plus <= 8.7.02.003 - Unauthenticated Arbitrary Shortcode Execution

medium

The WP Photo Album Plus plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 8.7.02.003. This is due to the plugin allowing unauthenticated users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unau...

CVSS:
6.5
Affected:
up to 8.7.00.003
Fixed in:
8.7.00.004
Disclosed:
May 23, 2024

CVE-2024-4037 on NVD →

WP Photo Album Plus [wp-photo-album-plus] < 8.7.01.002

unknown

[en] Unrestricted Upload of File with Dangerous Type vulnerability in J.N. Breetvelt a.K.A. OpaJaap WP Photo Album Plus.This issue affects WP Photo Album Plus: from n/a through 8.7.01.001.

Affected:
up to 8.7.01.002
Fixed in:
8.7.01.002
Disclosed:
May 13, 2024

CVE-2024-31377 on NVD →

WP Photo Album Plus <= 8.7.01.001 - Unauthenticated Arbitrary File Upload

critical

The WP Photo Album Plus plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation on the import functionality and no capability check in all versions up to, and including, 8.7.01.001. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected si...

CVSS:
10
Affected:
up to 8.7.01.001
Fixed in:
8.7.01.002
Disclosed:
May 7, 2024

CVE-2024-31377 on NVD →

WP Photo Album Plus [wp-photo-album-plus] < 8.6.03.005

unknown

[en] Unrestricted Upload of File with Dangerous Type vulnerability in J.N. Breetvelt a.K.A. OpaJaap WP Photo Album Plus.This issue affects WP Photo Album Plus: from n/a before 8.6.03.005.

Affected:
up to 8.6.03.005
Fixed in:
8.6.03.005
Disclosed:
Apr 7, 2024

CVE-2024-31286 on NVD →

WP Photo Album Plus <= 8.6.03.004 - Authenticated (Subscriber+) Arbitrary File Upload

critical

The WP Photo Album Plus plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the wppa_user_upload() function in all versions up to, and including, 8.6.03.004. This makes it possible for authenticated attackers, with subscriber-level access and above, to upload arbitrary fi...

CVSS:
9.9
Affected:
up to 8.6.03.004
Fixed in:
8.6.03.005
Disclosed:
Apr 5, 2024

CVE-2024-31286 on NVD →

WP Photo Album Plus [wp-photo-album-plus] < 8.6.01.005

unknown

[en] Authorization Bypass Through User-Controlled Key vulnerability in J.N. Breetvelt a.K.A. OpaJaap WP Photo Album Plus.This issue affects WP Photo Album Plus: from n/a through 8.5.02.005.

Affected:
up to 8.6.01.005
Fixed in:
8.6.01.005
Disclosed:
Dec 19, 2023

CVE-2023-49812 on NVD →

WP Photo Album Plus [wp-photo-album-plus] < 8.6.01.005

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in J.N. Breetvelt a.K.A. OpaJaap WP Photo Album Plus allows Stored XSS.This issue affects WP Photo Album Plus: from n/a through 8.5.02.005.

Affected:
up to 8.6.01.005
Fixed in:
8.6.01.005
Disclosed:
Dec 14, 2023

CVE-2023-49813 on NVD →

WP Photo Album Plus <= 8.5.02.005 - Cross-Site Scripting

medium

The WP Photo Album Plus plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 8.5.02.005 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user acce...

CVSS:
6.1
Affected:
up to 8.5.02.005
Fixed in:
8.6.01.005
Disclosed:
Dec 5, 2023

CVE-2023-49813 on NVD →

WP Photo Album Plus <= 8.5.02.005 - IP Spoofing

medium

The WP Photo Album Plus plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 8.5.02.005. This is due to insufficient restrictions on where the IP Address information is being retrieved for request logging and login restrictions. Attackers can supply a header that allows their IP a...

CVSS:
5.3
Affected:
up to 8.5.02.005
Fixed in:
8.6.01.005
Disclosed:
Dec 5, 2023

CVE-2023-49774 on NVD →

WP Photo Album Plus <= 8.5.02.005 - Insecure Direct Object Reference

medium

The WP Photo Album Plus plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 8.5.02.005 due to missing validation on a user controlled key. This makes it possible for unauthenticated attacker to perform an unauthorized action base don a user controlled key.

CVSS:
5.3
Affected:
up to 8.5.02.005
Fixed in:
8.6.01.005
Disclosed:
Dec 5, 2023

CVE-2023-49812 on NVD →

WP Photo Album Plus [wp-photo-album-plus] < 8.0.10

unknown

[en] The WP Photo Album Plus WordPress plugin before 8.0.10 was vulnerable to Stored Cross-Site Scripting (XSS). Error log content was handled improperly, therefore any user, even unauthenticated, could cause arbitrary javascript to be executed in the admin panel.

Affected:
up to 8.0.10
Fixed in:
8.0.10
Disclosed:
Feb 14, 2022

CVE-2021-25115 on NVD →

WP Photo Album Plus <= 8.0.10 - Stored Cross-Site Scripting

high

The WP Photo Album Plus WordPress plugin before 8.0.10 was vulnerable to Stored Cross-Site Scripting (XSS). Error log content was handled improperly, therefore any user, even unauthenticated, could cause arbitrary javascript to be executed in the admin panel.

CVSS:
7.2
Affected:
up to 8.0.10
Fixed in:
8.1.00
Disclosed:
Jan 2, 2022

CVE-2021-25115 on NVD →

WP Photo Album Plus [wp-photo-album-plus] < 5.4.5

unknown

This plugin is prone to a cross site scripting vulnerability. Update the plugin.

Affected:
up to 5.4.5
Fixed in:
5.4.5
Disclosed:
Jun 19, 2016

WP Photo Album Plus [wp-photo-album-plus] < 4.9.1

unknown

This plugin is prone to a full path disclosure vulnerability. Update the plugin.

Affected:
up to 4.9.1
Fixed in:
4.9.1
Disclosed:
Oct 18, 2015

WP Photo Album Plus [wp-photo-album-plus] < 6.1.3

unknown

[en] Multiple cross-site scripting (XSS) vulnerabilities in wppa-ajax-front.php in the WP Photo Album Plus (aka WPPA) plugin before 6.1.3 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) comemail or (2) comname parameter in a wppa do-comment action.

Affected:
up to 6.1.3
Fixed in:
6.1.3
Disclosed:
May 21, 2015

CVE-2015-3647 on NVD →

WP Photo Album Plus < 6.1.3 - Cross-Site Scripting

high

Multiple cross-site scripting (XSS) vulnerabilities in wppa-ajax-front.php in the WP Photo Album Plus (aka WPPA) plugin before 6.1.3 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) comemail or (2) comname parameter in a wppa do-comment action.

CVSS:
7.1
Affected:
up to 6.1.3
Fixed in:
6.1.3
Disclosed:
May 20, 2015

CVE-2015-3647 on NVD →

WP Photo Album Plus [wp-photo-album-plus] < 4.8.12

unknown

This plugin is prone to wp-photo-album-plus.php wppa-searchstring cross site scripting vulnerability Update the plugin.

Affected:
up to 4.8.12
Fixed in:
4.8.12
Disclosed:
May 15, 2015

WP Photo Album Plus [wp-photo-album-plus] < 5.4.9

unknown

This plugin is prone to a stored cross site scripting vulnerability. Update the plugin.

Affected:
up to 5.4.9
Fixed in:
5.4.9
Disclosed:
May 15, 2015

WP Photo Album Plus [wp-photo-album-plus] < 5.0.11

unknown

This plugin is prone to wp-admin/admin.php edit_id parameter cross site scripting vulnerability. Update the plugin.

Affected:
up to 5.0.11
Fixed in:
5.0.11
Disclosed:
May 15, 2015

WP Photo Album Plus [wp-photo-album-plus] < 4.9.3

unknown

This plugin is prone to index.php wppa-tag parameter cross site scripting vulnerability. Update the plugin.

Affected:
up to 4.9.3
Fixed in:
4.9.3
Disclosed:
May 15, 2015

WP Photo Album Plus <= 5.4.17 - Reflected Cross-Site Scripting

medium

The WP Photo Album Plus plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘walbum’ parameter in versions up to, and including, 5.4.17 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that...

CVSS:
6.1
Affected:
up to 5.4.17
Fixed in:
5.4.18
Disclosed:
Nov 6, 2014

CVE-2014-8814 on NVD →

WP Photo Album Plus <= 5.4.7 - Stored Cross-Site Scripting

medium

The WP Photo Album Plus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'zip' parameter in versions up to, and including, 5.4.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that will exec...

CVSS:
6.4
Affected:
up to 5.4.7
Fixed in:
5.4.8
Disclosed:
Sep 17, 2014

WP Photo Album Plus [wp-photo-album-plus] >= 5.4.5 - <= 5.4.8

unknown

The WP Photo Album Plus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'zip' parameter in versions up to, and including, 5.4.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that will exec...

Affected:
5.4.5 – 5.4.8
Fixed in:
5.4.8
Disclosed:
Sep 17, 2014

WP Photo Album Plus [wp-photo-album-plus] < 5.0.3

unknown

[en] Cross-site scripting (XSS) vulnerability in wp-admin/admin.php in the WP Photo Album Plus plugin before 5.0.3 for WordPress allows remote attackers to inject arbitrary web script or HTML via the commentid parameter in a wppa_manage_comments edit action.

Affected:
up to 5.0.3
Fixed in:
5.0.3
Disclosed:
May 10, 2013

CVE-2013-3254 on NVD →

WP Photo Album Plus < 5.0.3 - Cross-Site Scripting

medium

Cross-site scripting (XSS) vulnerability in wp-admin/admin.php in the WP Photo Album Plus plugin before 5.0.3 for WordPress allows remote attackers to inject arbitrary web script or HTML via the commentid parameter in a wppa_manage_comments edit action.

CVSS:
6.1
Affected:
up to 5.0.3
Fixed in:
5.0.3
Disclosed:
May 6, 2013

CVE-2013-3254 on NVD →

WP Photo Album Plus [wp-photo-album-plus] < 4.1.2

unknown

WPPhoto Album Plus plugin is prone to an SQL injection. This vulnerability allows an attacker to modify data, alter queries to the application SQL database, compromise the access and application or exploit hidden vulnerabilities in the underlying database. Update the plugin.

Affected:
up to 4.1.2
Fixed in:
4.1.2
Disclosed:
Oct 15, 2011

WP Photo Album Plus <= 1.1 - SQL Injection

critical

Multiple SQL injection vulnerabilities in wppa.php in the WP Photo Album (WPPA) before 1.1 plugin for WordPress allow remote attackers to execute arbitrary SQL commands via (1) the photo parameter to index.php, used by the wppa_photo_name function; or (2) the album parameter to index.php, used by the wppa_album_name fu...

CVSS:
9.8
Affected:
up to 1.0
Fixed in:
1.1
Disclosed:
Feb 25, 2008

CVE-2008-0939 on NVD →

WP Photo Album Plus [wp-photo-album-plus] < 4.2.0

unknown

The WP Photo Album Plus WordPress plugin was affected by a SQL Injection security vulnerability.

Affected:
up to 4.2.0
Fixed in:
4.2.0

WP Photo Album Plus [wp-photo-album-plus] < 5.4.5

unknown

The WP Photo Album Plus WordPress plugin was affected by security vulnerability.

Affected:
up to 5.4.5
Fixed in:
5.4.5

WP Photo Album Plus [wp-photo-album-plus] < 5.0.11

unknown

The WP Photo Album Plus WordPress plugin was affected by a wp-admin/admin.php edit_id Parameter XSS security vulnerability.

Affected:
up to 5.0.11
Fixed in:
5.0.11

WP Photo Album Plus [wp-photo-album-plus] < 4.9.3

unknown

The WP Photo Album Plus WordPress plugin was affected by an index.php wppa-tag Parameter XSS security vulnerability.

Affected:
up to 4.9.3
Fixed in:
4.9.3

WP Photo Album Plus [wp-photo-album-plus] < 4.9.1

unknown

The WP Photo Album Plus WordPress plugin was affected by a Full Path Disclosure security vulnerability.

Affected:
up to 4.9.1
Fixed in:
4.9.1

WP Photo Album Plus [wp-photo-album-plus] < 5.4.8

unknown

The WP Photo Album Plus WordPress plugin was affected by a 5.4.8 Stored XSS security vulnerability.

Affected:
up to 5.4.8
Fixed in:
5.4.8

WP Photo Album Plus [wp-photo-album-plus] < 4.8.12

unknown

The WP Photo Album Plus WordPress plugin was affected by a wp-photo-album-plus.php wppa-searchstring XSS security vulnerability.

Affected:
up to 4.8.12
Fixed in:
4.8.12

WP Photo Album Plus [wp-photo-album-plus] < 9.0.11.007

unknown
Affected:
up to 9.0.11.007
Fixed in:
9.0.11.007

CVE-2025-8726 on NVD →

WP Photo Album Plus [wp-photo-album-plus] < 5.4.18

unknown

** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Affected:
up to 5.4.18
Fixed in:
5.4.18

CVE-2014-8814 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database