Cross-Site Scripting Vulnerability in WP Photo Album Plus Plugin by WordPress
CVE-2013-3254
Currently unrated
Summary
The vulnerability allows remote attackers to exploit a cross-site scripting (XSS) weakness through the wp-admin/admin.php script in the WP Photo Album Plus plugin prior to version 5.0.3. By manipulating the commentid parameter during the wppa_manage_comments edit action, attackers can inject arbitrary web scripts or HTML, potentially leading to unauthorized access and data compromise for users of the affected plugin.
References
Timeline
Vulnerability Reserved
Vulnerability published