Cross-Site Scripting Vulnerability in WP Photo Album Plus Plugin by WordPress
CVE-2025-8726

5.4MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
4 October 2025

What is CVE-2025-8726?

The WP Photo Album Plus plugin for WordPress is susceptible to a cross-site scripting vulnerability across all versions up to and including 9.0.11.006. This weakness arises from inadequate input sanitization and output escaping within the wppa_user_upload function. Authenticated attackers with Subscriber-level access or higher can exploit this vulnerability to insert malicious web scripts into photo album descriptions. When victims view these descriptions, the scripts execute in their browsers, potentially leading to unauthorized actions and compromise of user data. Proper mitigation requires upgrading to the latest version of the plugin and reviewing input sanitization practices.

Affected Version(s)

WP Photo Album Plus * <= 9.0.11.006

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

D.Sim
.