Impact
This vulnerability is an unauthenticated Cross Site Scripting (XSS) flaw, identified as CWE‑79, that allows an attacker to inject malicious scripts into the WordPress WP Photo Album Plus plugin pages. The injected code is executed in the context of a site visitor, potentially enabling cookie theft, defacement, or execution of arbitrary actions on behalf of authenticated users. The impact is limited to the scope of a single site.
Affected Systems
The flaw affects the WordPress WP Photo Album Plus plugin developed by Jacob N. Breetvelt, specifically versions 9.3.02.002 and all prior releases. Sites running any of these versions are susceptible regardless of user authentication status.
Risk and Exploitability
The CVSS score of 7.1 indicates a moderate to high severity, while the EPSS score is not available, leaving the likelihood of exploitation uncertain. The vulnerability is not listed in the CISA KEV catalog, but its unauthenticated nature means that any visitor to the affected plugin pages can trigger the flaw. Given the potential consequences of script execution and the absence of mitigating controls, the risk is considered high, warranting prompt mitigation.
OpenCVE Enrichment