Cross-Site Scripting Vulnerability in WP Photo Album Plus Plugin by WordPress
CVE-2025-8726
What is CVE-2025-8726?
The WP Photo Album Plus plugin for WordPress is susceptible to a cross-site scripting vulnerability across all versions up to and including 9.0.11.006. This weakness arises from inadequate input sanitization and output escaping within the wppa_user_upload function. Authenticated attackers with Subscriber-level access or higher can exploit this vulnerability to insert malicious web scripts into photo album descriptions. When victims view these descriptions, the scripts execute in their browsers, potentially leading to unauthorized actions and compromise of user data. Proper mitigation requires upgrading to the latest version of the plugin and reviewing input sanitization practices.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
WP Photo Album Plus * <= 9.0.11.006
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved