Description
The WP Photo Album Plus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REQUEST_URI Session History in all versions up to, and including, 9.3.03.002 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The bypass works because esc_url_raw() strips literal angle brackets but retains HTML entities, which wppaEntityDecode() silently converts back to live HTML tags before jQuery('#wppa-modal-container').html() renders them.
Published: 2026-10-10
Score: 7.2 High
EPSS: n/a
KEV: No
Impact: Stored Cross‑Site Scripting
Action: Patch
AI Analysis

Impact

WP Photo Album Plus, a WordPress plugin, stores the REQUEST_URI value in a session history buffer. The sanitization routine uses esc_url_raw(), which removes literal angle brackets but keeps HTML entities. The wppaEntityDecode() function later converts these entities back into live HTML tags, and the content is rendered by jQuery('#wppa-modal-container').html(). Because of this flaw, an attacker can inject arbitrary JavaScript that will execute in the browsers of any visitor whose page renders the corrupted session entry. The CVE description does not specify additional capabilities such as credential theft or redirection beyond the execution of supplied scripts.

Affected Systems

WordPress sites that use the WP Photo Album Plus plugin distributed under the opajaap namespace, specifically any installation running version 9.3.03.002 or any earlier release.

Risk and Exploitability

Based on the description, it is inferred that an unauthenticated attacker can craft a URL that stores malicious code in the session history; it is also inferred that this payload will be rendered when a visitor browses a page that displays the session buffer. The stored payload remains on the server until the session history is cleared or the plugin is upgraded. The vulnerability receives a CVSS score of 7.2, indicating a high severity risk. EPSS is not available and the flaw is not listed in the CISA KEV catalog. The attack vector is therefore unauthenticated and relies on influencing a user’s browser to visit a victim page where the injected JavaScript executes.

Generated by OpenCVE AI on October 10, 2026 at 10:51 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade WP Photo Album Plus to the latest version that removes the XSS vulnerability.
  • Disable or remove the session‑history feature that stores REQUEST_URI in the session buffer until a patch can be applied.
  • Deploy a web application firewall or a comprehensive WordPress security plugin that filters or blocks XSS payloads before they reach the rendering logic.

Generated by OpenCVE AI on October 10, 2026 at 10:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 10 Oct 2026 08:00:00 +0000

Type Values Removed Values Added
Description The WP Photo Album Plus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REQUEST_URI Session History in all versions up to, and including, 9.3.03.002 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The bypass works because esc_url_raw() strips literal angle brackets but retains HTML entities, which wppaEntityDecode() silently converts back to live HTML tags before jQuery('#wppa-modal-container').html() renders them.
Title WP Photo Album Plus <= 9.3.03.002 - Unauthenticated Stored Cross-Site Scripting via REQUEST_URI Session History
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-10-10T07:41:42.244Z

Reserved: 2026-09-22T20:43:20.770Z

Link: CVE-2026-96278

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-10T08:17:07.567

Modified: 2026-10-10T08:17:07.567

Link: CVE-2026-96278

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-10T11:00:13Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')