Junglewise Threat Intelligence

CVE-2026-57675: Jacob N. Breetvelt WP Photo Album Plus unauthenticated XSS

CVE-2026-57675 · Severity: high · CVSS 7.1 · Published 2026-07-02

Technologies: Jacob N. Breetvelt WP Photo Album Plus.

Executive brief

WP Photo Album Plus, a WordPress plugin used for managing and displaying photo galleries, is vulnerable to a security flaw that allows attackers to inject malicious scripts into the website. If a site administrator or visitor interacts with a specially crafted link or page, the attacker could potentially hijack user sessions, redirect visitors to malicious websites, or deface the site. This vulnerability can be exploited by remote attackers without needing to log in to the site.

Technical details

A Cross-Site Scripting (XSS) vulnerability exists in the WP Photo Album Plus plugin for WordPress due to improper neutralization of user-supplied input (CWE-79). The flaw allows an unauthenticated remote attacker to inject malicious JavaScript into web pages generated by the plugin. Exploitation requires a victim (typically a site administrator) to perform an action, such as clicking a malicious link or visiting a specific page (User Interaction required). Successful exploitation can lead to session hijacking, unauthorized actions in the context of the victim's browser, or the delivery of further browser-based exploits. The issue is resolved in version 9.2.03.001.

Affected products

  • Jacob N. Breetvelt WP Photo Album Plus <= 9.2.02.004

Timeline

  • 2026-06-17: disclosed: Reported by Nguyen Ba Khanh
  • 2026-06-30: advisory: Patchstack advisory published
  • 2026-07-02: advisory: NVD published CVE-2026-57675
  • 2026-06-30: patched: Version 9.2.03.001 released to address the issue

References