Junglewise Threat Intelligence

CVE-2026-10095: WP Photo Album Plus Stored XSS in subtext parameter

CVE-2026-10095 · Severity: medium · CVSS 6.4 · Published 2026-07-01

Technologies: Opajaap WP Photo Album Plus.

Executive brief

The WP Photo Album Plus plugin for WordPress, which is used to manage and display photo galleries, contains a security flaw that allows users with low-level access (like contributors) to inject malicious scripts into website pages. When an administrator or another visitor views the affected page, these scripts can execute automatically, potentially leading to unauthorized actions or data theft. This could compromise the security of the website and its users if a contributor submits a post for review containing the malicious code.

Technical details

A Stored Cross-Site Scripting (XSS) vulnerability exists in the WP Photo Album Plus plugin for WordPress due to insufficient input sanitization and output escaping of the 'subtext' parameter within the [photo] shortcode. Authenticated attackers with contributor-level permissions or higher can exploit this by embedding a malicious shortcode into a post. When a user, such as an administrator reviewing the post, accesses the page, the injected script executes in their browser context. The vulnerability is present in all versions up to and including 9.1.13.005 and has been addressed in subsequent updates.

Affected products

  • opajaap WP Photo Album Plus up to, and including, 9.1.13.005

Timeline

  • 2026-07-01: advisory: NVD publication date
  • 2026-07-01: disclosed: Wordfence advisory published

References