Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

WP Photo Album Plus — Vulnerabilities & Security Advisories 21

All 21 CVE vulnerabilities found in WP Photo Album Plus, with AI-generated Chinese analysis, references, and POCs.

This page documents security weaknesses affecting WP Photo Album Plus, a widely used WordPress plugin developed by Joomlashack, categorized under various weakness types. It aggregates known vulnerabilities found in this specific product, covering security issues reported and analyzed from 2011 through 2024. By examining this collection, users can effectively track the vendor’s advisory history to understand how quickly security fixes are deployed following disclosure. Visitors can also deepen their comprehension of specific weakness classes prevalent in legacy WordPress plugins, observing how common flaws like cross-site scripting or unauthorized access manifest in real-world software. Furthermore, this resource allows developers and site administrators to look up a product's full vulnerability history, providing context on the evolution of security postures over time. This historical perspective helps in assessing the long-term maintenance quality of the plugin and identifying potential risks in older versions that may still be in use. The data presented is derived from public reports, vendor notices, and community findings, offering a transparent view of the plugin's security landscape. Understanding these patterns is crucial for maintaining secure WordPress environments, as it highlights the importance of regular updates and patch management. This aggregated view serves as a reference for security researchers, IT professionals, and WordPress site owners seeking to mitigate risks associated with this specific tool. The page does not include promotional content or subjective evaluations, focusing solely on factual security data to aid in informed decision-making regarding the continued use or upgrade of this software component.

Vendor: Unknown

CVE IDTitleCVSSSeverityPublished
CVE-2026-17014 WP Photo Album Plus < 9.2.07.002 - Unauthenticated Export ZIP File Deletion via delexportzips --2026-08-09
CVE-2026-14922 WP Photo Album Plus < 9.2.04.003 - Subscriber+ Stored XSS via Photo Comment --2026-07-31
CVE-2026-15344 WP Photo Album Plus <= 9.2.04.002 - Authenticated (Administrator+) SQL Injection via 'table' Parameter CWE-89 4.9 Medium2026-07-29
CVE-2026-57675 WordPress WP Photo Album Plus plugin <= 9.2.02.004 - Cross Site Scripting (XSS) vulnerability CWE-79 7.1 High2026-07-02
CVE-2026-10095 WP Photo Album Plus <= 9.1.13.005 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'subtext' Shortcode Attribute CWE-79 6.4 Medium2026-07-01
CVE-2026-54829 WordPress WP Photo Album Plus plugin <= 9.1.13.005 - SQL Injection vulnerability CWE-89 7.5 High2026-06-25
CVE-2026-39511 WordPress WP Photo Album Plus plugin <= 9.1.08.001 - SQL Injection vulnerability CWE-89 9.3 Critical2026-06-15
CVE-2026-6379 WP Photo Album Plus < 9.1.11.001 - Unauthenticated SQL Injection via 'wppa-supersearch' Parameter --2026-05-18
CVE-2025-14835 WP Photo Album Plus <= 9.1.05.008 - Reflected Cross-Site Scripting CWE-80 7.1 High2026-01-07
CVE-2025-8726 WP Photo Album Plus <= 9.0.11.006 - Authenticated (Subscriber+) Stored Cross-Site Scripting via wppa_user_upload CWE-79 5.4 Medium2025-10-04
CVE-2024-10958 WP Photo Album Plus <= 8.8.08.007 - Unauthenticated Arbitrary Shortcode Execution via getshortcodedrenderedfenodelay CWE-94 7.3 High2024-11-10
CVE-2024-9951 Wordpress Photo Album Plus <= 8.8.05.003 - Reflected Cross-Site Scripting CWE-79 6.1 Medium2024-10-17
CVE-2024-37416 WordPress WP Photo Album Plus plugin <= 8.8.00.002 - Reflected Cross Site Scripting (XSS) vulnerability CWE-79 7.1 High2024-07-22
CVE-2024-38713 WordPress WP Photo Album Plus plugin <= 8.8.02.002 - Authenticated Stored Cross Site Scripting (XSS) vulnerability CWE-79 6.5 Medium2024-07-20
CVE-2023-49774 WordPress WP Photo Album Plus plugin <= 8.5.02.005 - IP Bypass vulnerability CWE-200 5.3 Medium2024-06-04
CVE-2024-4037 WP Photo Album Plus <= 8.7.02.003 - Unauthenticated Arbitrary Shortcode Execution CWE-94 6.5 Medium2024-05-24
CVE-2024-31377 WordPress WP Photo Album Plus plugin <= 8.7.01.001 - Unauth. Arbitrary File Upload vulnerability CWE-434 10.0 Critical2024-05-13
CVE-2024-31286 WordPress WP Photo Album Plus plugin < 8.6.03.005 - Arbitrary File Upload vulnerability CWE-434 9.9 Critical2024-04-07
CVE-2023-49812 WordPress WP Photo Album Plus Plugin <= 8.5.02.005 is vulnerable to Insecure Direct Object References (IDOR) CWE-639 5.3 Medium2023-12-19
CVE-2023-49813 WordPress WP Photo Album Plus Plugin <= 8.5.02.005 is vulnerable to Cross Site Scripting (XSS) CWE-79 7.1 High2023-12-14
CVE-2021-25115 WP Photo Album Plus < 8.0.10 - Stored Cross-Site Scripting (XSS) CWE-79 5.4 -2022-02-14

All 21 known CVE vulnerabilities affecting WP Photo Album Plus with full Chinese analysis, references, and POCs where available.