๐Ÿ” CVE Alert

CVE-2026-18579

HIGH 7.2

WP Photo Album Plus <= 9.2.08.003 - Unauthenticated Stored Cross-Site Scripting

CVSS Score
7.2
EPSS Score
0.0%
EPSS Percentile
0th

The WP Photo Album Plus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'HTTP_X_FORWARDED_FOR' parameter in all versions up to, and including, 9.2.08.003 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The nonce failure path for the getshortcodedrenderedfenodelay action serves as the log-write trigger rather than an access barrier โ€” a deliberately failed nonce check causes wppa_log() to record the attacker-supplied X-Forwarded-For value to disk, making the exploit fully reachable by unauthenticated callers via the wp_ajax_nopriv_wppa endpoint.

CWE CWE-79
Vendor opajaap
Product wp photo album plus
Published Sep 11, 2026
Last Updated Sep 11, 2026
Stay Ahead of the Next One

Get instant alerts for opajaap wp photo album plus

Be the first to know when new high vulnerabilities affecting opajaap wp photo album plus are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

opajaap / WP Photo Album Plus
0 โ‰ค 9.2.08.003

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wordfence.com: https://www.wordfence.com/threat-intel/vulnerabilities/id/251943ed-65d2-4635-9c84-2cf671233543?source=cve plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/wp-photo-album-plus/tags/9.2.08.003/js/wppa-admin-scripts.js#L2069 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/wp-photo-album-plus/tags/9.2.08.003/wppa-input.php#L560 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/wp-photo-album-plus/tags/9.2.08.003/wppa-utils.php#L1960 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/wp-photo-album-plus/tags/9.2.08.003/wppa-ajax.php#L1246 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/wp-photo-album-plus/tags/9.2.07.002/js/wppa-admin-scripts.js#L2069 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/wp-photo-album-plus/tags/9.2.07.002/wppa-input.php#L560 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/wp-photo-album-plus/tags/9.2.07.002/wppa-utils.php#L1960 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/wp-photo-album-plus/tags/9.2.07.002/wppa-ajax.php#L1246 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3641521%40wp-photo-album-plus%2Ftrunk%2Fjs%2Fwppa-admin-scripts.js&old=3625666%40wp-photo-album-plus%2Ftrunk%2Fjs%2Fwppa-admin-scripts.js&sfp_email=&sfph_mail= plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3641521%40wp-photo-album-plus%2Ftrunk%2Fwppa-input.php&old=3619969%40wp-photo-album-plus%2Ftrunk%2Fwppa-input.php&sfp_email=&sfph_mail=

Credits

Jonah Burgess (CryptoCat)