Impact
A cross‑site scripting flaw exists in the WP Photo Album Plus plugin up to and including version 9.3.02.003. The vulnerability allows malicious scripts to be injected through user‑supplied input that the plugin renders without sufficient escaping, potentially leading to defacement, cookie theft, or session hijacking for visitors viewing the affected content. The weakness is identified as CWE‑79, and the impact is limited to the web interface where the plugin accepts user input.
Affected Systems
The issue affects the WordPress WP Photo Album Plus plugin delivered by Jacob N. Breetvelt, specifically all releases up to and including 9.3.02.003. Versions 9.3.03.002 and later contain the fix and are not impacted.
Risk and Exploitability
With a CVSS score of 6.5, the vulnerability is considered moderate. No EPSS score is available, and the vulnerability is not listed in CISA’s KEV catalog, indicating low publicly known exploitation activity. The attack vector is remote: an attacker can submit crafted payloads through the plugin’s subscriber interface, which renders the data without proper escaping.
OpenCVE Enrichment