Extension WordPress
Vulnérabilités WP Photo Album Plus
Cette page rassemble les failles publiées pour WP Photo Album Plus, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de WP Photo Album Plus
23 fiches
WP Photo Album Plus <= 9.1.13.005 – Authenticated (Contributor+) Stored Cross-Site Scripting via 'subtext' Shortcode Attribute
The WP Photo Album Plus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'subtext' parameter in all versions up to, and including, 9.1.13.005 due to insufficient input sanitization and output escaping. This makes it possible…
*-9.1.13.005
9.2.01.001
30/06/2026
WP Photo Album Plus <= 9.2.02.004 – Unauthenticated Stored Cross-Site Scripting
The WP Photo Album Plus plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 9.2.02.004 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject…
*-9.2.02.004
9.2.03.001
30/06/2026
WP Photo Album Plus <= 9.1.13.005 – Unauthenticated SQL Injection
The WP Photo Album Plus plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 9.1.13.005 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL…
*-9.1.13.005
9.2.01.001
17/06/2026
WP Photo Album Plus < 9.1.11.001 – Unauthenticated SQL Injection
The WP Photo Album Plus plugin for WordPress is vulnerable to SQL Injection in versions up to 9.1.11.001 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This…
[*, 9.1.11.001)
9.1.11.001
11/06/2026
WP Photo Album Plus <= 9.1.08.001 – Unauthenticated SQL Injection
The WP Photo Album Plus plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 9.1.08.001 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL…
*-9.1.08.001
9.1.08.002
13/04/2026
WP Photo Album Plus <= 9.1.05.008 – Reflected Cross-Site Scripting
The WP Photo Album Plus plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘shortcode’ parameter in all versions up to, and including, 9.1.05.008 due to insufficient input sanitization and output escaping. This makes it possible…
*-9.1.05.008
9.1.05.009
06/01/2026
WP Photo Album Plus <= 9.0.11.006 – Authenticated (Subscriber+) Stored Cross-Site Scripting via wppa_user_upload
The WP Photo Album Plus plugin for WordPress is vulnerable to Cross-Site Scripting in all versions up to, and including, 9.0.11.006 due to insufficient input sanitization and output escaping in the wppa_user_upload function. This makes it possible for…
*-9.0.11.006
9.0.11.007
03/10/2025
WP Photo Album Plus <= 8.8.08.007 – Unauthenticated Arbitrary Shortcode Execution via getshortcodedrenderedfenodelay
The The WP Photo Album Plus plugin for WordPress is vulnerable to arbitrary shortcode execution via getshortcodedrenderedfenodelay AJAX action in all versions up to, and including, 8.8.08.007 . This is due to the software allowing users to execute…
*-8.8.08.007
8.9.01.001
10/11/2024
Wordpress Photo Album Plus <= 8.8.05.003 – Reflected Cross-Site Scripting
The WP Photo Album Plus plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wppa-tab' parameter in all versions up to, and including, 8.8.05.003 due to insufficient input sanitization and output escaping. This makes it possible…
*-8.8.05.003
8.8.07.004
16/10/2024
WP Photo Album Plus <= 8.8.02.002 – Authenticated (Subscriber+) Stored Cross-Site Scripting
The WP Photo Album Plus plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 8.8.02.002 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level…
*-8.8.02.002
8.8.02.003
11/07/2024
WP Photo Album Plus <= 8.8.00.002 – Reflected Cross-Site Scripting
The WP Photo Album Plus plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 8.8.00.002 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject…
*-8.8.00.002
8.8.00.003
28/06/2024
WP Photo Album Plus <= 8.7.02.003 – Unauthenticated Arbitrary Shortcode Execution
The WP Photo Album Plus plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 8.7.02.003. This is due to the plugin allowing unauthenticated users to execute an action that does not…
*-8.7.00.003
8.7.00.004
23/05/2024
WP Photo Album Plus <= 8.7.01.001 – Unauthenticated Arbitrary File Upload
The WP Photo Album Plus plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation on the import functionality and no capability check in all versions up to, and including, 8.7.01.001. This makes…
*-8.7.01.001
8.7.01.002
07/05/2024
WP Photo Album Plus <= 8.6.03.004 – Authenticated (Subscriber+) Arbitrary File Upload
The WP Photo Album Plus plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the wppa_user_upload() function in all versions up to, and including, 8.6.03.004. This makes it possible for authenticated…
*-8.6.03.004
8.6.03.005
05/04/2024
WP Photo Album Plus <= 8.5.02.005 – Insecure Direct Object Reference
The WP Photo Album Plus plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 8.5.02.005 due to missing validation on a user controlled key. This makes it possible for unauthenticated…
*-8.5.02.005
8.6.01.005
05/12/2023
WP Photo Album Plus <= 8.5.02.005 – IP Spoofing
The WP Photo Album Plus plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 8.5.02.005. This is due to insufficient restrictions on where the IP Address information is being retrieved for request…
*-8.5.02.005
8.6.01.005
05/12/2023
WP Photo Album Plus <= 8.5.02.005 – Cross-Site Scripting
The WP Photo Album Plus plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 8.5.02.005 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary…
*-8.5.02.005
8.6.01.005
05/12/2023
WP Photo Album Plus <= 8.0.10 – Stored Cross-Site Scripting
The WP Photo Album Plus WordPress plugin before 8.0.10 was vulnerable to Stored Cross-Site Scripting (XSS). Error log content was handled improperly, therefore any user, even unauthenticated, could cause arbitrary javascript to be executed in the admin panel.
[*, 8.0.10)
8.1.00
02/01/2022
WP Photo Album Plus < 6.1.3 – Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in wppa-ajax-front.php in the WP Photo Album Plus (aka WPPA) plugin before 6.1.3 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) comemail or (2) comname parameter…
[*, 6.1.3)
6.1.3
20/05/2015
WP Photo Album Plus <= 5.4.17 – Reflected Cross-Site Scripting
The WP Photo Album Plus plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘walbum’ parameter in versions up to, and including, 5.4.17 due to insufficient input sanitization and output escaping. This makes it possible for…
*-5.4.17
5.4.18
06/11/2014
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.