Impact
An unauthenticated Cross Site Scripting flaw exists in the WP Photo Album Plus plugin up to version 9.2.02.004. By inserting malicious JavaScript into the plugin’s output, a visitor can execute arbitrary code in the target user’s browser. The underlying weakness is identified as CWE‑79, an input validation flaw that fails to sanitize received data.
Affected Systems
WordPress sites that have installed the WP Photo Album Plus plugin by Jacob N. Breetvelt are affected. Any installation using version 9.2.02.004 or earlier is vulnerable, regardless of the WordPress core version or other plugins.
Risk and Exploitability
The CVSS score of 7.1 and the EPSS score of < 1% indicate a low but nonzero probability of exploitation, and the vulnerability is not included in CISA’s KEV catalog. The likely attack vector is that the plugin receives and reflects data without sufficient sanitization; this inference comes from the description that the vulnerability is unauthenticated XSS. While no publicly disclosed exploit has surfaced, the minimal effort needed to craft a payload suggests that the vulnerability is readily exploitable by attackers capable of injecting script into the plugin’s output.
OpenCVE Enrichment