CVE-2025-27361
WordPress Photo Express for Google plugin <= 0.3.2 - Reflected Cross Site Scripting (XSS) vulnerability
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in thhake Photo Express for Google photo-express-for-google allows Reflected XSS.This issue affects Photo Express for Google: from n/a through <= 0.3.2.
| CWE | CWE-79 |
| Vendor | thhake |
| Product | photo express for google |
| Published | Jun 27, 2025 |
| Last Updated | Apr 1, 2026 |
Stay Ahead of the Next One
Get instant alerts for thhake photo express for google
Be the first to know when new unknown vulnerabilities affecting thhake photo express for google are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
thhake / Photo Express for Google
0 ≤ 0.3.2
References
Credits
João Pedro S Alcântara (Kinorth) | Patchstack Bug Bounty Program