CVE-2021-25115: WP Photo Album Plus < 8.0.10 - Stored Cross-Site Scripting (XSS)
Published Feb 14, 2022
·Updated
The WP Photo Album Plus WordPress plugin before 8.0.10 was vulnerable to Stored Cross-Site Scripting (XSS). Error log content was handled improperly, therefore any user, even unauthenticated, could cause arbitrary javascript to be executed in the admin panel.
Affected Software
2 affected components
Wp Photo Album Plus Project Wp Photo Album Plus Wordpress<8.0.10
Wppa Wp Photo Album Plus Wordpress<8.0.10.006
Remediation
Event History
Feb 14, 2022
CVE Published
via MITRE·09:20 AM
Data Sourced
via MITRE·09:20 AM
DescriptionWeakness
Data Sourced
via NVD·12:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2021-25115?
The severity of CVE-2021-25115 is classified as medium with a CVSS score of 6.4.
2
How does CVE-2021-25115 affect WP Photo Album Plus plugin?
CVE-2021-25115 affects the WP Photo Album Plus plugin before version 8.0.10, making it vulnerable to Stored Cross-Site Scripting (XSS) attacks.
3
Is CVE-2021-25115 exploited by authenticated users only?
No, CVE-2021-25115 can be exploited by any user, even if they are unauthenticated, to execute arbitrary JavaScript in the admin panel.