Sceawere

Vulnerability Detail

CVE-2026-96278UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

WP Photo Album Plus Stored XSS

Vulnerability Metadata

Severity
High
Score / CVSS
7.2
Creation Date
2h ago
Vendor
opajaap
Product
WP Photo Album Plus
Attack Type
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

The WP Photo Album Plus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REQUEST_URI Session History in all versions up to, and including, 9.3.03.002 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The bypass works because esc_url_raw() strips literal angle brackets but retains HTML entities, which wppaEntityDecode() silently converts back to live HTML tags before jQuery('#wppa-modal-container').html() renders them.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.2",
  "pubDate": "2026-10-10T08:17:07.567Z",
  "pubdate": "2026-10-10T08:17:07.567Z",
  "executiveSummary": "The WP Photo Album Plus plugin for WordPress contains a critical Stored Cross-Site Scripting (XSS) vulnerability affecting all versions up to and including 9.3.03.002.\nThe vulnerability stems from improper input sanitization and inadequate output escaping within the plugin's session history tracking mechanism.\nAn unauthenticated attacker can inject arbitrary malicious JavaScript into the REQUEST_URI, which is subsequently persisted within the application's session state.\nWhen a victim, including administrators, accesses a page where this session data is rendered, the payload executes within the context of the user's browser session.\nThis vulnerability poses a significant risk, as successful exploitation could lead to unauthorized actions performed on behalf of the victim, session hijacking, or exfiltration of sensitive information.\nNo authentication or specific user privileges are required to initiate the attack, as the injection occurs via publicly accessible URL parameters or headers that populate the REQUEST_URI.\nGiven the nature of the rendering process, this flaw enables a persistent compromise of any user browsing the affected content.",
  "technicalDetails": "The vulnerability resides in the way WP Photo Album Plus processes and stores the REQUEST_URI within the user's session history. The plugin attempts to sanitize this input using esc_url_raw(), but this function is insufficient for preventing XSS in this specific context.\nThe core issue involves a security bypass where esc_url_raw() successfully strips literal angle brackets (< and >) from the input string; however, it fails to neutralize HTML entities. An attacker can craft a payload using encoded characters (e.g., &lt;script&gt;) which pass the initial sanitization layer intact.\nUpon retrieval from the session storage, the plugin utilizes a custom function, wppaEntityDecode(), to process the stored data. This function silently decodes the HTML entities back into their functional, executable counterparts—effectively reconstituting the script tags that were initially filtered.\nThe final stage of the attack occurs during the client-side rendering phase. The application passes this decoded content directly to the jQuery('#wppa-modal-container').html() function. Because jQuery's .html() method interprets strings as HTML, the reconstituted script tags are parsed and executed by the browser engine.\nThe attack flow proceeds as follows: 1) The attacker crafts a request containing an XSS payload encoded as HTML entities within the REQUEST_URI. 2) The WordPress server records this URI in the session history. 3) The plugin processes the URI using wppaEntityDecode(), which converts the entities into active HTML tags. 4) The application injects the processed string into the DOM via the jQuery modal container. 5) The victim's browser executes the injected script.\nThis vulnerability is highly exploitable because it does not require the attacker to have administrative access or a pre-existing session. The injection mechanism is reachable through any standard HTTP request that populates the server-side REQUEST_URI environment variable.\nPost-exploitation, an attacker can manipulate the DOM, steal session cookies via document.cookie, perform unauthorized administrative actions if the victim is an authorized user, or redirect users to malicious domains. The impact is persistent, as the injected script resides in the session history until the session is cleared or overwritten."
}
CVE-2026-96278: WP Photo Album Plus Stored XSS (HIGH Severity, CVSS: 7.2) | Sceawere