Sceawere
Vulnerability Detail
CVE-2026-102386UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
WP Photo Album Plus XSS
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.5
- Creation Date
- 3h ago
- Vendor
- Jacob N. Breetvelt
- Product
- WP Photo Album Plus
- Attack Type
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
Subscriber Cross Site Scripting (XSS) in WP Photo Album Plus <= 9.3.02.003 versions.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.5",
"pubDate": "2026-09-30T13:17:17.243Z",
"pubdate": "2026-09-30T13:17:17.243Z",
"executiveSummary": "The WP Photo Album Plus plugin for WordPress, specifically versions 9.3.02.003 and earlier, contains a stored Cross-Site Scripting (XSS) vulnerability. This vulnerability is classified as a subscriber-level XSS, allowing authenticated users with low-level privileges to inject malicious client-side scripts into the application. The vulnerability resides in the way the plugin handles user-supplied input before rendering it in the dashboard or frontend interface. When an attacker successfully injects a payload, the script is stored in the database and subsequently executed within the browser session of other users, including administrators, when they view the affected page. This exposure poses a significant risk, as it facilitates the potential theft of session cookies, administrative account takeover, unauthorized actions on behalf of the victim, and unauthorized data exfiltration. Exploitation requires the attacker to hold at least a subscriber-level account, making it a critical concern for multi-user WordPress environments where user registration is enabled. The vulnerability highlights a failure in input validation and output encoding mechanisms within the plugin's data processing logic.",
"technicalDetails": "The vulnerability is a stored Cross-Site Scripting (XSS) flaw localized within the WP Photo Album Plus plugin. It arises from insufficient input sanitization and improper output encoding of user-controlled data processed by the plugin. Specifically, the plugin fails to adequately filter or encode data supplied via user-controlled parameters before storing it in the WordPress database.\nThe attack flow begins with an authenticated user, such as a subscriber, submitting a crafted payload through input fields provided by the WP Photo Album Plus plugin. Because the plugin does not implement rigorous server-side validation or effective output escaping (e.g., using WordPress functions like esc_html() or esc_js()) during the storage or retrieval process, the malicious payload remains persisted in the database.\nWhen a victim, such as a site administrator or another high-privileged user, navigates to the affected administrative page or a specific frontend view where the plugin renders the malicious data, the browser interprets the stored content as executable code. This occurs because the injected script tags are rendered directly into the HTML document object model (DOM) without proper character conversion, thereby bypassing browser-level XSS protections.\nThe exploitation of this vulnerability allows for the execution of arbitrary JavaScript within the context of the victim's session. An attacker could craft a payload designed to perform several malicious activities: capturing sensitive administrative session tokens to achieve session hijacking, forcing the user's browser to perform unauthorized requests (CSRF), or redirecting the user to malicious external sites. Since the script executes within the context of the legitimate WordPress domain, it bypasses Same-Origin Policy (SOP) restrictions, enabling full access to the document, cookies, and local storage associated with the application.\nThe flaw affects all versions of WP Photo Album Plus up to and including 9.3.02.003. The primary root cause is the reliance on insecure data handling practices for user-submitted content. As the plugin is intended for use in potentially multi-user environments, this vulnerability demonstrates a failure to enforce the principle of least privilege, as low-privileged users are effectively permitted to inject code that affects higher-privileged entities. The vulnerability is network-exploitable, assuming the attacker has the capability to log in to the system as a standard subscriber."
}