Impact
The WP Photo Album Plus plugin has a stored cross‑site scripting vulnerability (CWE-79) in the ‘subtext’ attribute of the [photo] shortcode. The flaw originates from insufficient input sanitization and output escaping. An authenticated contributor or higher attacker can inject arbitrary JavaScript, causing the malicious code to execute whenever a post containing the injected shortcode is viewed.
Affected Systems
WordPress sites that use the opajaap WP Photo Album Plus plugin at version 9.1.13.005 or earlier are vulnerable to a stored cross‑site scripting flaw.
Risk and Exploitability
The CVSS score of 6.4 indicates moderate severity. The EPSS score of <1% reflects a very low probability of exploitation at the current time. The vulnerability is not listed in the CISA KEV catalog. The attack vector requires a user with contributor‑level privileges, making the risk contingent on the site's role configuration.
OpenCVE Enrichment