Executive brief
WP Photo Album Plus is a popular WordPress plugin for displaying photo galleries. The plugin fails to properly sanitize user input in the lbstart parameter, allowing attackers to inject malicious scripts into pages containing galleries. An attacker can craft a link that, when clicked by a visitor, executes arbitrary JavaScript in the user's browser session, enabling account takeover or data theft.
Technical details
The vulnerability is a Reflected Cross-Site Scripting (XSS) flaw in the WP Photo Album Plus plugin versions before 9.2.07.002. The plugin fails to sanitize and escape the lbstart URL parameter before reflecting it into an inline script block. An unauthenticated attacker can inject JavaScript code (e.g., via a URL-encoded payload like ;alert(document.domain);x=) into a gallery page, causing the payload to execute in the victim's browser when the page loads. No authentication or user interaction beyond clicking a malicious link is required. The vulnerability is fixed in version 9.2.07.002 or later.
Affected products
- Automattic WP Photo Album Plus before 9.2.07.002
Timeline
- 2026-08-10: disclosed
- 2026-08-12: patched: Fixed in version 9.2.07.002