Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-32423 | The WP Photo Album Plus plugin for WordPress is vulnerable to Cross-Site Scripting in all versions up to, and including, 9.0.11.006 due to insufficient input sanitization and output escaping in the wppa_user_upload function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts in the photo album descriptions that execute in a victim's browser. |
Mon, 06 Oct 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 06 Oct 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Opajaap
Opajaap wp Photo Album Plus Wordpress Wordpress wordpress |
|
| Vendors & Products |
Opajaap
Opajaap wp Photo Album Plus Wordpress Wordpress wordpress |
Sat, 04 Oct 2025 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The WP Photo Album Plus plugin for WordPress is vulnerable to Cross-Site Scripting in all versions up to, and including, 9.0.11.006 due to insufficient input sanitization and output escaping in the wppa_user_upload function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts in the photo album descriptions that execute in a victim's browser. | |
| Title | WP Photo Album Plus <= 9.0.11.006 - Authenticated (Subscriber+) Stored Cross-Site Scripting via wppa_user_upload | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T16:54:20.055Z
Reserved: 2025-08-08T01:09:06.550Z
Link: CVE-2025-8726
Updated: 2025-10-06T14:18:35.492Z
Status : Deferred
Published: 2025-10-04T03:15:38.123
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-8726
No data.
OpenCVE Enrichment
Updated: 2026-04-21T02:45:25Z
EUVD