Impact
WP Photo Album Plus, a WordPress plugin, stores the REQUEST_URI value in a session history buffer. The sanitization routine uses esc_url_raw(), which removes literal angle brackets but keeps HTML entities. The wppaEntityDecode() function later converts these entities back into live HTML tags, and the content is rendered by jQuery('#wppa-modal-container').html(). Because of this flaw, an attacker can inject arbitrary JavaScript that will execute in the browsers of any visitor whose page renders the corrupted session entry. The CVE description does not specify additional capabilities such as credential theft or redirection beyond the execution of supplied scripts.
Affected Systems
WordPress sites that use the WP Photo Album Plus plugin distributed under the opajaap namespace, specifically any installation running version 9.3.03.002 or any earlier release.
Risk and Exploitability
Based on the description, it is inferred that an unauthenticated attacker can craft a URL that stores malicious code in the session history; it is also inferred that this payload will be rendered when a visitor browses a page that displays the session buffer. The stored payload remains on the server until the session history is cleared or the plugin is upgraded. The vulnerability receives a CVSS score of 7.2, indicating a high severity risk. EPSS is not available and the flaw is not listed in the CISA KEV catalog. The attack vector is therefore unauthenticated and relies on influencing a user’s browser to visit a victim page where the injected JavaScript executes.
OpenCVE Enrichment