The WP Photo Album Plus WordPress plugin before 8.0.10 was vulnerable to Stored Cross-Site Scripting (XSS). Error log content was handled improperly, therefore any user, even unauthenticated, could cause arbitrary javascript to be executed in the admin panel.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-12027 | The WP Photo Album Plus WordPress plugin before 8.0.10 was vulnerable to Stored Cross-Site Scripting (XSS). Error log content was handled improperly, therefore any user, even unauthenticated, could cause arbitrary javascript to be executed in the admin panel. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 20 Mar 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wppa
Wppa wp Photo Album Plus |
|
| CPEs | cpe:2.3:a:wppa:wp_photo_album_plus:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Wp Photo Album Plus Project
Wp Photo Album Plus Project wp Photo Album Plus |
Wppa
Wppa wp Photo Album Plus |
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2024-08-03T19:56:10.439Z
Reserved: 2021-01-14T00:00:00.000Z
Link: CVE-2021-25115
No data.
Status : Analyzed
Published: 2022-02-14T12:15:15.490
Modified: 2026-03-20T18:34:03.680
Link: CVE-2021-25115
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD