Impact
In WP Photo Album Plus, a stored XSS flaw allows attackers to submit the value of the HTTP_X_FORWARDED_FOR header, which is logged to disk because a deliberately failed nonce check writes the header via wppa_log(). The attacker‑supplied value is then served to any user who views the affected page, enabling arbitrary code execution in the victim’s browser, session hijacking, and site defacement. The vulnerability is fully exploitable without authentication and does not require users to click a link, making it pose a high risk to any visitor of the affected WordPress site.
Affected Systems
The flaw exists in the WP Photo Album Plus WordPress plugin for versions up to and including 9.2.08.003. Users running any of these releases, regardless of the site’s configuration, are susceptible.
Risk and Exploitability
The CVSS severity is 7.2, indicating a high‑impact vulnerability. No EPSS value is available, and the flaw is not yet listed in the CISA KEV catalog. Because the attack vector is wp_ajax_nopriv_wppa with no authentication required, attackers can trigger the exploit simply by sending a crafted HTTP request containing a malicious HTTP_X_FORWARDED_FOR header. Once the value is recorded, any visitor who accesses the affected page will have the script executed in their browser. The combination of unauthenticated access and persistent data storage creates a significant threat that can be leveraged to compromise site integrity and user data.
OpenCVE Enrichment