Cross-Site Scripting Vulnerability in WP Photo Album Plus Plugin by WordPress
CVE-2025-8726
5.4MEDIUM
What is CVE-2025-8726?
The WP Photo Album Plus plugin for WordPress is susceptible to a cross-site scripting vulnerability across all versions up to and including 9.0.11.006. This weakness arises from inadequate input sanitization and output escaping within the wppa_user_upload function. Authenticated attackers with Subscriber-level access or higher can exploit this vulnerability to insert malicious web scripts into photo album descriptions. When victims view these descriptions, the scripts execute in their browsers, potentially leading to unauthorized actions and compromise of user data. Proper mitigation requires upgrading to the latest version of the plugin and reviewing input sanitization practices.
Affected Version(s)
WP Photo Album Plus * <= 9.0.11.006