WP Photo Album Plus < 9.2.07.002 - Missing Authorization
medium
The WP Photo Album Plus plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to 9.2.07.002. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 9.2.07.002
- Fixed in:
- 9.2.07.002
- Disclosed:
- Aug 14, 2026
CVE-2026-18049 on NVD →
WP Photo Album Plus < 9.2.04.003 - Authenticated (Subscriber+) Stored Cross-Site Scripting
medium
The WP Photo Album Plus plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 9.2.04.003 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that wil...
- CVSS:
- 6.4
- Affected:
- up to 9.2.04.003
- Fixed in:
- 9.2.04.003
- Disclosed:
- Aug 13, 2026
CVE-2026-14922 on NVD →
Photo Album Plus <= 9.2.07.1 - Arbitrary File Deletion to Unauthenticated Arbitrary ZIP File Deletion
critical
The Photo Album Plus plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 9.2.07.1. This is due to insufficient validation of a user supplied path. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can lead to a site takeover w...
- CVSS:
- 9.1
- Affected:
- up to 9.2.07.1
- Fixed in:
- 9.2.07.002
- Disclosed:
- Aug 10, 2026
CVE-2026-18048 on NVD →
Photo Album Plus <= 9.2.07.1 - Reflected Cross-Site Scripting
medium
The Photo Album Plus plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 9.2.07.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successf...
- CVSS:
- 6.1
- Affected:
- up to 9.2.07.1
- Fixed in:
- 9.2.07.002
- Disclosed:
- Aug 10, 2026
CVE-2026-17013 on NVD →
Photo Album Plus <= 9.2.09.1 - Missing Authorization
medium
The Photo Album Plus plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 9.2.09.1. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.
- CVSS:
- 4.3
- Affected:
- up to 9.2.09.1
- Fixed in:
- 9.2.09.002
- Disclosed:
- Aug 10, 2026
CVE-2026-18962 on NVD →
Photo Album Plus <= 9.2.07.1 - Unauthenticated Export ZIP File Deletion
medium
The Photo Album Plus plugin for WordPress is vulnerable to Arbitrary Zip File Deletion in versions up to, and including, 9.2.07.1. This is due to insufficient validation of a user supplied path. This makes it possible for unauthenticated attackers to delete arbitrary zip files on the server.
- CVSS:
- 5.3
- Affected:
- up to 9.2.07.1
- Fixed in:
- 9.2.07.002
- Disclosed:
- Aug 3, 2026
CVE-2026-17014 on NVD →
WP Photo Album Plus <= 9.2.04.002 - Authenticated (Administrator+) SQL Injection via 'table' Parameter
medium
The WP Photo Album Plus plugin for WordPress is vulnerable to generic SQL Injection via the 'table' parameter in all versions up to, and including, 9.2.04.002 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticate...
- CVSS:
- 4.9
- Affected:
- up to 9.2.04.002
- Fixed in:
- 9.2.04.003
- Disclosed:
- Jul 28, 2026
CVE-2026-15344 on NVD →
WP Photo Album Plus <= 9.1.13.005 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'subtext' Shortcode Attribute
medium
The WP Photo Album Plus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'subtext' parameter in all versions up to, and including, 9.1.13.005 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above,...
- CVSS:
- 6.4
- Affected:
- up to 9.1.13.005
- Fixed in:
- 9.2.01.001
- Disclosed:
- Jun 30, 2026
CVE-2026-10095 on NVD →
WP Photo Album Plus <= 9.2.02.004 - Unauthenticated Stored Cross-Site Scripting
high
The WP Photo Album Plus plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 9.2.02.004 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a us...
- CVSS:
- 7.2
- Affected:
- up to 9.2.02.004
- Fixed in:
- 9.2.03.001
- Disclosed:
- Jun 30, 2026
CVE-2026-57675 on NVD →
WP Photo Album Plus <= 9.1.13.005 - Unauthenticated SQL Injection
high
The WP Photo Album Plus plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 9.1.13.005 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL...
- CVSS:
- 7.5
- Affected:
- up to 9.1.13.005
- Fixed in:
- 9.2.01.001
- Disclosed:
- Jun 17, 2026
CVE-2026-54829 on NVD →
WP Photo Album Plus < 9.1.11.001 - Unauthenticated SQL Injection
high
The WP Photo Album Plus plugin for WordPress is vulnerable to SQL Injection in versions up to 9.1.11.001 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into al...
- CVSS:
- 7.5
- Affected:
- up to 9.1.11.001
- Fixed in:
- 9.1.11.001
- Disclosed:
- Jun 11, 2026
CVE-2026-6379 on NVD →
WP Photo Album Plus <= 9.1.08.001 - Unauthenticated SQL Injection
high
The WP Photo Album Plus plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 9.1.08.001 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL...
- CVSS:
- 7.5
- Affected:
- up to 9.1.08.001
- Fixed in:
- 9.1.08.002
- Disclosed:
- Apr 13, 2026
CVE-2026-39511 on NVD →
WP Photo Album Plus [wp-photo-album-plus] < 9.1.05.009
unknown
[en] The WP Photo Album Plus plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘shortcode’ parameter in all versions up to, and including, 9.1.05.008 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web script...
- Affected:
- up to 9.1.05.009
- Fixed in:
- 9.1.05.009
- Disclosed:
- Jan 7, 2026
CVE-2025-14835 on NVD →
WP Photo Album Plus <= 9.1.05.008 - Reflected Cross-Site Scripting
high
The WP Photo Album Plus plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘shortcode’ parameter in all versions up to, and including, 9.1.05.008 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in...
- CVSS:
- 7.1
- Affected:
- up to 9.1.05.008
- Fixed in:
- 9.1.05.009
- Disclosed:
- Jan 6, 2026
CVE-2025-14835 on NVD →
WP Photo Album Plus <= 9.0.11.006 - Authenticated (Subscriber+) Stored Cross-Site Scripting via wppa_user_upload
medium
The WP Photo Album Plus plugin for WordPress is vulnerable to Cross-Site Scripting in all versions up to, and including, 9.0.11.006 due to insufficient input sanitization and output escaping in the wppa_user_upload function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to...
- CVSS:
- 5.4
- Affected:
- up to 9.0.11.006
- Fixed in:
- 9.0.11.007
- Disclosed:
- Oct 3, 2025
CVE-2025-8726 on NVD →
WP Photo Album Plus <= 8.8.08.007 - Unauthenticated Arbitrary Shortcode Execution via getshortcodedrenderedfenodelay
high
The The WP Photo Album Plus plugin for WordPress is vulnerable to arbitrary shortcode execution via getshortcodedrenderedfenodelay AJAX action in all versions up to, and including, 8.8.08.007 . This is due to the software allowing users to execute an action that does not properly validate a value before running do_shor...
- CVSS:
- 7.3
- Affected:
- up to 8.8.08.007
- Fixed in:
- 8.9.01.001
- Disclosed:
- Nov 10, 2024
CVE-2024-10958 on NVD →
WP Photo Album Plus [wp-photo-album-plus] < 8.9.01.001
unknown
[en] The The WP Photo Album Plus plugin for WordPress is vulnerable to arbitrary shortcode execution via getshortcodedrenderedfenodelay AJAX action in all versions up to, and including, 8.8.08.007 . This is due to the software allowing users to execute an action that does not properly validate a value before running do...
- Affected:
- up to 8.9.01.001
- Fixed in:
- 8.9.01.001
- Disclosed:
- Nov 10, 2024
CVE-2024-10958 on NVD →
WP Photo Album Plus [wp-photo-album-plus] < 8.8.07.004
unknown
[en] The WP Photo Album Plus plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wppa-tab' parameter in all versions up to, and including, 8.8.05.003 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts...
- Affected:
- up to 8.8.07.004
- Fixed in:
- 8.8.07.004
- Disclosed:
- Oct 17, 2024
CVE-2024-9951 on NVD →
Wordpress Photo Album Plus <= 8.8.05.003 - Reflected Cross-Site Scripting
medium
The WP Photo Album Plus plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wppa-tab' parameter in all versions up to, and including, 8.8.05.003 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in p...
- CVSS:
- 6.1
- Affected:
- up to 8.8.05.003
- Fixed in:
- 8.8.07.004
- Disclosed:
- Oct 16, 2024
CVE-2024-9951 on NVD →
WP Photo Album Plus [wp-photo-album-plus] < 8.8.00.003
unknown
[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in J.N. Breetvelt a.K.A. OpaJaap WP Photo Album Plus allows Reflected XSS.This issue affects WP Photo Album Plus: from n/a through 8.8.00.002.
- Affected:
- up to 8.8.00.003
- Fixed in:
- 8.8.00.003
- Disclosed:
- Jul 22, 2024
CVE-2024-37416 on NVD →
WP Photo Album Plus [wp-photo-album-plus] < 8.8.02.003
unknown
[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in J.N. Breetvelt a.K.A. OpaJaap WP Photo Album Plus allows Stored XSS.This issue affects WP Photo Album Plus: from n/a through 8.8.02.002.
- Affected:
- up to 8.8.02.003
- Fixed in:
- 8.8.02.003
- Disclosed:
- Jul 20, 2024
CVE-2024-38713 on NVD →
WP Photo Album Plus <= 8.8.02.002 - Authenticated (Subscriber+) Stored Cross-Site Scripting
medium
The WP Photo Album Plus plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 8.8.02.002 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts i...
- CVSS:
- 6.4
- Affected:
- up to 8.8.02.002
- Fixed in:
- 8.8.02.003
- Disclosed:
- Jul 11, 2024
CVE-2024-38713 on NVD →
WP Photo Album Plus <= 8.8.00.002 - Reflected Cross-Site Scripting
medium
The WP Photo Album Plus plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 8.8.00.002 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can suc...
- CVSS:
- 6.1
- Affected:
- up to 8.8.00.002
- Fixed in:
- 8.8.00.003
- Disclosed:
- Jun 28, 2024
CVE-2024-37416 on NVD →
WP Photo Album Plus [wp-photo-album-plus] < 8.6.01.005
unknown
[en] Exposure of Sensitive Information to an Unauthorized Actor vulnerability in J.N. Breetvelt a.K.A. OpaJaap WP Photo Album Plus allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WP Photo Album Plus: from n/a through 8.5.02.005.
- Affected:
- up to 8.6.01.005
- Fixed in:
- 8.6.01.005
- Disclosed:
- Jun 4, 2024
CVE-2023-49774 on NVD →
WP Photo Album Plus [wp-photo-album-plus] < 8.7.00.004
unknown
[en] The WP Photo Album Plus plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 8.7.02.003. This is due to the plugin allowing unauthenticated users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for...
- Affected:
- up to 8.7.00.004
- Fixed in:
- 8.7.00.004
- Disclosed:
- May 24, 2024
CVE-2024-4037 on NVD →
WP Photo Album Plus <= 8.7.02.003 - Unauthenticated Arbitrary Shortcode Execution
medium
The WP Photo Album Plus plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 8.7.02.003. This is due to the plugin allowing unauthenticated users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unau...
- CVSS:
- 6.5
- Affected:
- up to 8.7.00.003
- Fixed in:
- 8.7.00.004
- Disclosed:
- May 23, 2024
CVE-2024-4037 on NVD →
WP Photo Album Plus [wp-photo-album-plus] < 8.7.01.002
unknown
[en] Unrestricted Upload of File with Dangerous Type vulnerability in J.N. Breetvelt a.K.A. OpaJaap WP Photo Album Plus.This issue affects WP Photo Album Plus: from n/a through 8.7.01.001.
- Affected:
- up to 8.7.01.002
- Fixed in:
- 8.7.01.002
- Disclosed:
- May 13, 2024
CVE-2024-31377 on NVD →
WP Photo Album Plus <= 8.7.01.001 - Unauthenticated Arbitrary File Upload
critical
The WP Photo Album Plus plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation on the import functionality and no capability check in all versions up to, and including, 8.7.01.001. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected si...
- CVSS:
- 10
- Affected:
- up to 8.7.01.001
- Fixed in:
- 8.7.01.002
- Disclosed:
- May 7, 2024
CVE-2024-31377 on NVD →
WP Photo Album Plus [wp-photo-album-plus] < 8.6.03.005
unknown
[en] Unrestricted Upload of File with Dangerous Type vulnerability in J.N. Breetvelt a.K.A. OpaJaap WP Photo Album Plus.This issue affects WP Photo Album Plus: from n/a before 8.6.03.005.
- Affected:
- up to 8.6.03.005
- Fixed in:
- 8.6.03.005
- Disclosed:
- Apr 7, 2024
CVE-2024-31286 on NVD →
WP Photo Album Plus <= 8.6.03.004 - Authenticated (Subscriber+) Arbitrary File Upload
critical
The WP Photo Album Plus plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the wppa_user_upload() function in all versions up to, and including, 8.6.03.004. This makes it possible for authenticated attackers, with subscriber-level access and above, to upload arbitrary fi...
- CVSS:
- 9.9
- Affected:
- up to 8.6.03.004
- Fixed in:
- 8.6.03.005
- Disclosed:
- Apr 5, 2024
CVE-2024-31286 on NVD →
WP Photo Album Plus [wp-photo-album-plus] < 8.6.01.005
unknown
[en] Authorization Bypass Through User-Controlled Key vulnerability in J.N. Breetvelt a.K.A. OpaJaap WP Photo Album Plus.This issue affects WP Photo Album Plus: from n/a through 8.5.02.005.
- Affected:
- up to 8.6.01.005
- Fixed in:
- 8.6.01.005
- Disclosed:
- Dec 19, 2023
CVE-2023-49812 on NVD →
WP Photo Album Plus [wp-photo-album-plus] < 8.6.01.005
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in J.N. Breetvelt a.K.A. OpaJaap WP Photo Album Plus allows Stored XSS.This issue affects WP Photo Album Plus: from n/a through 8.5.02.005.
- Affected:
- up to 8.6.01.005
- Fixed in:
- 8.6.01.005
- Disclosed:
- Dec 14, 2023
CVE-2023-49813 on NVD →
WP Photo Album Plus <= 8.5.02.005 - Cross-Site Scripting
medium
The WP Photo Album Plus plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 8.5.02.005 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user acce...
- CVSS:
- 6.1
- Affected:
- up to 8.5.02.005
- Fixed in:
- 8.6.01.005
- Disclosed:
- Dec 5, 2023
CVE-2023-49813 on NVD →
WP Photo Album Plus <= 8.5.02.005 - IP Spoofing
medium
The WP Photo Album Plus plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 8.5.02.005. This is due to insufficient restrictions on where the IP Address information is being retrieved for request logging and login restrictions. Attackers can supply a header that allows their IP a...
- CVSS:
- 5.3
- Affected:
- up to 8.5.02.005
- Fixed in:
- 8.6.01.005
- Disclosed:
- Dec 5, 2023
CVE-2023-49774 on NVD →
WP Photo Album Plus <= 8.5.02.005 - Insecure Direct Object Reference
medium
The WP Photo Album Plus plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 8.5.02.005 due to missing validation on a user controlled key. This makes it possible for unauthenticated attacker to perform an unauthorized action base don a user controlled key.
- CVSS:
- 5.3
- Affected:
- up to 8.5.02.005
- Fixed in:
- 8.6.01.005
- Disclosed:
- Dec 5, 2023
CVE-2023-49812 on NVD →
WP Photo Album Plus [wp-photo-album-plus] < 8.0.10
unknown
[en] The WP Photo Album Plus WordPress plugin before 8.0.10 was vulnerable to Stored Cross-Site Scripting (XSS). Error log content was handled improperly, therefore any user, even unauthenticated, could cause arbitrary javascript to be executed in the admin panel.
- Affected:
- up to 8.0.10
- Fixed in:
- 8.0.10
- Disclosed:
- Feb 14, 2022
CVE-2021-25115 on NVD →
WP Photo Album Plus <= 8.0.10 - Stored Cross-Site Scripting
high
The WP Photo Album Plus WordPress plugin before 8.0.10 was vulnerable to Stored Cross-Site Scripting (XSS). Error log content was handled improperly, therefore any user, even unauthenticated, could cause arbitrary javascript to be executed in the admin panel.
- CVSS:
- 7.2
- Affected:
- up to 8.0.10
- Fixed in:
- 8.1.00
- Disclosed:
- Jan 2, 2022
CVE-2021-25115 on NVD →
WP Photo Album Plus [wp-photo-album-plus] < 5.4.5
unknown
This plugin is prone to a cross site scripting vulnerability.
Update the plugin.
- Affected:
- up to 5.4.5
- Fixed in:
- 5.4.5
- Disclosed:
- Jun 19, 2016
WP Photo Album Plus [wp-photo-album-plus] < 4.9.1
unknown
This plugin is prone to a full path disclosure vulnerability.
Update the plugin.
- Affected:
- up to 4.9.1
- Fixed in:
- 4.9.1
- Disclosed:
- Oct 18, 2015
WP Photo Album Plus [wp-photo-album-plus] < 6.1.3
unknown
[en] Multiple cross-site scripting (XSS) vulnerabilities in wppa-ajax-front.php in the WP Photo Album Plus (aka WPPA) plugin before 6.1.3 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) comemail or (2) comname parameter in a wppa do-comment action.
- Affected:
- up to 6.1.3
- Fixed in:
- 6.1.3
- Disclosed:
- May 21, 2015
CVE-2015-3647 on NVD →
WP Photo Album Plus < 6.1.3 - Cross-Site Scripting
high
Multiple cross-site scripting (XSS) vulnerabilities in wppa-ajax-front.php in the WP Photo Album Plus (aka WPPA) plugin before 6.1.3 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) comemail or (2) comname parameter in a wppa do-comment action.
- CVSS:
- 7.1
- Affected:
- up to 6.1.3
- Fixed in:
- 6.1.3
- Disclosed:
- May 20, 2015
CVE-2015-3647 on NVD →
WP Photo Album Plus [wp-photo-album-plus] < 4.8.12
unknown
This plugin is prone to wp-photo-album-plus.php wppa-searchstring cross site scripting vulnerability
Update the plugin.
- Affected:
- up to 4.8.12
- Fixed in:
- 4.8.12
- Disclosed:
- May 15, 2015
WP Photo Album Plus [wp-photo-album-plus] < 5.4.9
unknown
This plugin is prone to a stored cross site scripting vulnerability.
Update the plugin.
- Affected:
- up to 5.4.9
- Fixed in:
- 5.4.9
- Disclosed:
- May 15, 2015
WP Photo Album Plus [wp-photo-album-plus] < 5.0.11
unknown
This plugin is prone to wp-admin/admin.php edit_id parameter cross site scripting vulnerability.
Update the plugin.
- Affected:
- up to 5.0.11
- Fixed in:
- 5.0.11
- Disclosed:
- May 15, 2015
WP Photo Album Plus [wp-photo-album-plus] < 4.9.3
unknown
This plugin is prone to index.php wppa-tag parameter cross site scripting vulnerability.
Update the plugin.
- Affected:
- up to 4.9.3
- Fixed in:
- 4.9.3
- Disclosed:
- May 15, 2015
WP Photo Album Plus <= 5.4.17 - Reflected Cross-Site Scripting
medium
The WP Photo Album Plus plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘walbum’ parameter in versions up to, and including, 5.4.17 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that...
- CVSS:
- 6.1
- Affected:
- up to 5.4.17
- Fixed in:
- 5.4.18
- Disclosed:
- Nov 6, 2014
CVE-2014-8814 on NVD →
WP Photo Album Plus <= 5.4.7 - Stored Cross-Site Scripting
medium
The WP Photo Album Plus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'zip' parameter in versions up to, and including, 5.4.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that will exec...
- CVSS:
- 6.4
- Affected:
- up to 5.4.7
- Fixed in:
- 5.4.8
- Disclosed:
- Sep 17, 2014
WP Photo Album Plus [wp-photo-album-plus] >= 5.4.5 - <= 5.4.8
unknown
The WP Photo Album Plus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'zip' parameter in versions up to, and including, 5.4.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that will exec...
- Affected:
- 5.4.5 – 5.4.8
- Fixed in:
- 5.4.8
- Disclosed:
- Sep 17, 2014
WP Photo Album Plus [wp-photo-album-plus] < 5.0.3
unknown
[en] Cross-site scripting (XSS) vulnerability in wp-admin/admin.php in the WP Photo Album Plus plugin before 5.0.3 for WordPress allows remote attackers to inject arbitrary web script or HTML via the commentid parameter in a wppa_manage_comments edit action.
- Affected:
- up to 5.0.3
- Fixed in:
- 5.0.3
- Disclosed:
- May 10, 2013
CVE-2013-3254 on NVD →
WP Photo Album Plus < 5.0.3 - Cross-Site Scripting
medium
Cross-site scripting (XSS) vulnerability in wp-admin/admin.php in the WP Photo Album Plus plugin before 5.0.3 for WordPress allows remote attackers to inject arbitrary web script or HTML via the commentid parameter in a wppa_manage_comments edit action.
- CVSS:
- 6.1
- Affected:
- up to 5.0.3
- Fixed in:
- 5.0.3
- Disclosed:
- May 6, 2013
CVE-2013-3254 on NVD →
WP Photo Album Plus [wp-photo-album-plus] < 4.1.2
unknown
WPPhoto Album Plus plugin is prone to an SQL injection. This vulnerability allows an attacker to modify data, alter queries to the application SQL database, compromise the access and application or exploit hidden vulnerabilities in the underlying database.
Update the plugin.
- Affected:
- up to 4.1.2
- Fixed in:
- 4.1.2
- Disclosed:
- Oct 15, 2011
WP Photo Album Plus <= 1.1 - SQL Injection
critical
Multiple SQL injection vulnerabilities in wppa.php in the WP Photo Album (WPPA) before 1.1 plugin for WordPress allow remote attackers to execute arbitrary SQL commands via (1) the photo parameter to index.php, used by the wppa_photo_name function; or (2) the album parameter to index.php, used by the wppa_album_name fu...
- CVSS:
- 9.8
- Affected:
- up to 1.0
- Fixed in:
- 1.1
- Disclosed:
- Feb 25, 2008
CVE-2008-0939 on NVD →
WP Photo Album Plus [wp-photo-album-plus] < 4.2.0
unknown
The WP Photo Album Plus WordPress plugin was affected by a SQL Injection security vulnerability.
- Affected:
- up to 4.2.0
- Fixed in:
- 4.2.0
WP Photo Album Plus [wp-photo-album-plus] < 5.4.5
unknown
The WP Photo Album Plus WordPress plugin was affected by security vulnerability.
- Affected:
- up to 5.4.5
- Fixed in:
- 5.4.5
WP Photo Album Plus [wp-photo-album-plus] < 5.0.11
unknown
The WP Photo Album Plus WordPress plugin was affected by a wp-admin/admin.php edit_id Parameter XSS security vulnerability.
- Affected:
- up to 5.0.11
- Fixed in:
- 5.0.11
WP Photo Album Plus [wp-photo-album-plus] < 4.9.3
unknown
The WP Photo Album Plus WordPress plugin was affected by an index.php wppa-tag Parameter XSS security vulnerability.
- Affected:
- up to 4.9.3
- Fixed in:
- 4.9.3
WP Photo Album Plus [wp-photo-album-plus] < 4.9.1
unknown
The WP Photo Album Plus WordPress plugin was affected by a Full Path Disclosure security vulnerability.
- Affected:
- up to 4.9.1
- Fixed in:
- 4.9.1
WP Photo Album Plus [wp-photo-album-plus] < 5.4.8
unknown
The WP Photo Album Plus WordPress plugin was affected by a 5.4.8 Stored XSS security vulnerability.
- Affected:
- up to 5.4.8
- Fixed in:
- 5.4.8
WP Photo Album Plus [wp-photo-album-plus] < 4.8.12
unknown
The WP Photo Album Plus WordPress plugin was affected by a wp-photo-album-plus.php wppa-searchstring XSS security vulnerability.
- Affected:
- up to 4.8.12
- Fixed in:
- 4.8.12
WP Photo Album Plus [wp-photo-album-plus] < 9.0.11.007
unknown
- Affected:
- up to 9.0.11.007
- Fixed in:
- 9.0.11.007
CVE-2025-8726 on NVD →
WP Photo Album Plus [wp-photo-album-plus] < 5.4.18
unknown
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
- Affected:
- up to 5.4.18
- Fixed in:
- 5.4.18
CVE-2014-8814 on NVD →