Description
The WP Photo Album Plus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'HTTP_X_FORWARDED_FOR' parameter in all versions up to, and including, 9.2.08.003 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The nonce failure path for the getshortcodedrenderedfenodelay action serves as the log-write trigger rather than an access barrier — a deliberately failed nonce check causes wppa_log() to record the attacker-supplied X-Forwarded-For value to disk, making the exploit fully reachable by unauthenticated callers via the wp_ajax_nopriv_wppa endpoint.
Published: 2026-09-11
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross‑Site Scripting
Action: Patch Immediately
AI Analysis

Impact

In WP Photo Album Plus, a stored XSS flaw allows attackers to submit the value of the HTTP_X_FORWARDED_FOR header, which is logged to disk because a deliberately failed nonce check writes the header via wppa_log(). The attacker‑supplied value is then served to any user who views the affected page, enabling arbitrary code execution in the victim’s browser, session hijacking, and site defacement. The vulnerability is fully exploitable without authentication and does not require users to click a link, making it pose a high risk to any visitor of the affected WordPress site.

Affected Systems

The flaw exists in the WP Photo Album Plus WordPress plugin for versions up to and including 9.2.08.003. Users running any of these releases, regardless of the site’s configuration, are susceptible.

Risk and Exploitability

The CVSS severity is 7.2, indicating a high‑impact vulnerability. No EPSS value is available, and the flaw is not yet listed in the CISA KEV catalog. Because the attack vector is wp_ajax_nopriv_wppa with no authentication required, attackers can trigger the exploit simply by sending a crafted HTTP request containing a malicious HTTP_X_FORWARDED_FOR header. Once the value is recorded, any visitor who accesses the affected page will have the script executed in their browser. The combination of unauthenticated access and persistent data storage creates a significant threat that can be leveraged to compromise site integrity and user data.

Generated by OpenCVE AI on September 11, 2026 at 05:45 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade WP Photo Album Plus to version 9.2.09 or later, which removes the vulnerable logging path
  • If an upgrade is temporarily impossible, sanitize or strip the HTTP_X_FORWARDED_FOR header before it reaches wppa_log(), ensuring no attacker‑supplied payload is written to disk
  • Block or restrict the wp_ajax_nopriv_wppa endpoint for unauthenticated requests using a firewall rule or a security plugin

Generated by OpenCVE AI on September 11, 2026 at 05:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Opajaap
Opajaap wp Photo Album Plus
Wordpress
Wordpress wordpress
Vendors & Products Opajaap
Opajaap wp Photo Album Plus
Wordpress
Wordpress wordpress

Fri, 11 Sep 2026 04:00:00 +0000

Type Values Removed Values Added
Description The WP Photo Album Plus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'HTTP_X_FORWARDED_FOR' parameter in all versions up to, and including, 9.2.08.003 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The nonce failure path for the getshortcodedrenderedfenodelay action serves as the log-write trigger rather than an access barrier — a deliberately failed nonce check causes wppa_log() to record the attacker-supplied X-Forwarded-For value to disk, making the exploit fully reachable by unauthenticated callers via the wp_ajax_nopriv_wppa endpoint.
Title WP Photo Album Plus <= 9.2.08.003 - Unauthenticated Stored Cross-Site Scripting
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

Opajaap Wp Photo Album Plus
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-09-11T20:19:12.744Z

Reserved: 2026-08-02T15:04:16.371Z

Link: CVE-2026-18579

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-11T04:17:24.600

Modified: 2026-09-11T21:17:08.770

Link: CVE-2026-18579

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T18:30:13Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')