WordPress security by component
WP Photo Album Plus
Plugin description
WP Photo Album Plus is a WordPress component with 20 published CVE records in this archive. The latest tracked vulnerability was published Jul 02, 2026; the highest CVE/CNA score is 10.
Plugin slug:
wp-photo-album-plusLatest vulnerability
CVE-2026-57675: WP Photo Album Plus: Cross-site scripting
WP Photo Album Plus is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 9.2.02.004.
| Safe version |
|
||
|---|---|---|---|
| Jul 02, 2026 |
CVE-2026-57675
WP Photo Album Plus: Cross-site scripting
WP Photo Album Plus is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 9.2.02.004.
|
9.2.03.001 |
CVE7.1
NVDPending
|
| Jul 01, 2026 |
CVE-2026-10095
WP Photo Album Plus: Cross-site scripting
WP Photo Album Plus is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 9.1.13.005.
|
> 9.1.13.005 |
CVE6.4
NVDPending
|
| Jun 25, 2026 |
CVE-2026-54829
WP Photo Album Plus: SQL injection
WP Photo Album Plus is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data. The published affected range is n/a through 9.1.13.005.
|
9.2.01.001 |
CVE7.5
NVDPending
|
| Jun 15, 2026 |
CVE-2026-39511
WP Photo Album Plus: SQL injection
WP Photo Album Plus is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data. The published affected range is n/a through 9.1.08.001.
|
9.1.08.002 |
CVE9.3
NVDPending
|
| May 18, 2026 |
CVE-2026-6379
WP Photo Album Plus: SQL injection
WP Photo Album Plus is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data. The published affected range is < 9.1.11.001.
|
9.1.11.001 |
CVE8.6
NVDPending
|
| Jan 07, 2026 |
CVE-2025-14835
WP Photo Album Plus: Cross-site scripting
WP Photo Album Plus is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE7.1
NVDPending
|
| Oct 04, 2025 |
CVE-2025-8726
WP Photo Album Plus: Cross-site scripting
WP Photo Album Plus is affected by cross-site scripting. Exploitation requires at least subscriber-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.4
NVDPending
|
| Nov 10, 2024 |
CVE-2024-10958
The WP Photo Album Plus: A security weakness
The WP Photo Album Plus is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE7.3
NVDPending
|
| Oct 17, 2024 |
CVE-2024-9951
WP Photo Album Plus: Cross-site scripting
WP Photo Album Plus is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.1
NVDPending
|
| Jul 22, 2024 |
CVE-2024-37416
WP Photo Album Plus: Cross-site scripting
WP Photo Album Plus is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE7.1
NVD6.1
|
| Jul 20, 2024 |
CVE-2024-38713
WP Photo Album Plus: Cross-site scripting
WP Photo Album Plus is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVDPending
|
| Jun 04, 2024 |
CVE-2023-49774
WP Photo Album Plus: A security weakness
WP Photo Album Plus is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVDPending
|
| May 24, 2024 |
CVE-2024-4037
WP Photo Album Plus: A security weakness
WP Photo Album Plus is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE6.5
NVD7.3
|
| May 14, 2024 |
CVE-2024-31377
WP Photo Album Plus: Dangerous file upload
WP Photo Album Plus is affected by dangerous file upload. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can place attacker-controlled executable content on the server and may lead to full site compromise.
|
See mitigation notes |
CVE10.0
NVDPending
|
| Apr 07, 2024 |
CVE-2024-31286
WP Photo Album Plus: Dangerous file upload
WP Photo Album Plus is affected by dangerous file upload. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can place attacker-controlled executable content on the server and may lead to full site compromise.
|
See mitigation notes |
CVE9.9
NVDPending
|
| Dec 19, 2023 |
CVE-2023-49812
WP Photo Album Plus: A security weakness
WP Photo Album Plus is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVD7.5
|
| Dec 14, 2023 |
CVE-2023-49813
WP Photo Album Plus: Cross-site scripting
WP Photo Album Plus is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE7.1
NVD6.1
|
| Feb 14, 2022 |
CVE-2021-25115
WP Photo Album Plus: Cross-site scripting
WP Photo Album Plus is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVD6.4
|
| May 21, 2015 |
CVE-2015-3647
Wp Photo Album Plus: Cross-site scripting
Wp Photo Album Plus is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE4.3
NVD4.3
|
| May 10, 2013 |
CVE-2013-3254
Wp Photo Album Plus: Cross-site scripting
Wp Photo Album Plus is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE4.3
NVD4.3
|