Junglewise Threat Intelligence

CVE-2026-17013: WordPress WP Photo Album Plus Reflected XSS via lbstart parameter

CVE-2026-17013 · Severity: medium · CVSS 6.1 · Published 2026-08-12

Vendors: Automattic.

Executive brief

WP Photo Album Plus is a popular WordPress plugin for displaying photo galleries. The plugin fails to properly sanitize user input in the lbstart parameter, allowing attackers to inject malicious scripts into pages containing galleries. An attacker can craft a link that, when clicked by a visitor, executes arbitrary JavaScript in the user's browser session, enabling account takeover or data theft.

Technical details

The vulnerability is a Reflected Cross-Site Scripting (XSS) flaw in the WP Photo Album Plus plugin versions before 9.2.07.002. The plugin fails to sanitize and escape the lbstart URL parameter before reflecting it into an inline script block. An unauthenticated attacker can inject JavaScript code (e.g., via a URL-encoded payload like ;alert(document.domain);x=) into a gallery page, causing the payload to execute in the victim's browser when the page loads. No authentication or user interaction beyond clicking a malicious link is required. The vulnerability is fixed in version 9.2.07.002 or later.

Affected products

  • Automattic WP Photo Album Plus before 9.2.07.002

Timeline

  • 2026-08-10: disclosed
  • 2026-08-12: patched: Fixed in version 9.2.07.002

References