Executive brief
The WP Photo Album Plus plugin for WordPress, which is used to manage and display photo galleries, contains a security flaw that allows users with low-level access (like contributors) to inject malicious scripts into website pages. When an administrator or another visitor views the affected page, these scripts can execute automatically, potentially leading to unauthorized actions or data theft. This could compromise the security of the website and its users if a contributor submits a post for review containing the malicious code.
Technical details
A Stored Cross-Site Scripting (XSS) vulnerability exists in the WP Photo Album Plus plugin for WordPress due to insufficient input sanitization and output escaping of the 'subtext' parameter within the [photo] shortcode. Authenticated attackers with contributor-level permissions or higher can exploit this by embedding a malicious shortcode into a post. When a user, such as an administrator reviewing the post, accesses the page, the injected script executes in their browser context. The vulnerability is present in all versions up to and including 9.1.13.005 and has been addressed in subsequent updates.
Affected products
- opajaap WP Photo Album Plus up to, and including, 9.1.13.005
Timeline
- 2026-07-01: advisory: NVD publication date
- 2026-07-01: disclosed: Wordfence advisory published
References
- https://plugins.trac.wordpress.org/browser/wp-photo-album-plus/tags/9.1.09.005/wppa-filter.php
- https://plugins.trac.wordpress.org/browser/wp-photo-album-plus/tags/9.1.09.005/wppa-filter.php
- https://plugins.trac.wordpress.org/browser/wp-photo-album-plus/tags/9.1.09.005/wppa-filter.php
- https://plugins.trac.wordpress.org/browser/wp-photo-album-plus/tags/9.1.09.005/wppa-functions.php
- https://plugins.trac.wordpress.org/browser/wp-photo-album-plus/tags/9.1.13.005/wppa-filter.php
- https://plugins.trac.wordpress.org/browser/wp-photo-album-plus/tags/9.1.13.005/wppa-filter.php
- https://plugins.trac.wordpress.org/browser/wp-photo-album-plus/tags/9.1.13.005/wppa-filter.php