CVE-2025-8726: WP Photo Album Plus <= 9.0.11.006 - Authenticated (Subscriber+) Stored Cross-Site Scripting via wppa_user_upload
The WP Photo Album Plus plugin for WordPress is vulnerable to Cross-Site Scripting in all versions up to, and including, 9.0.11.006 due to insufficient input sanitization and output escaping in the wppauserupload function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts in the photo album descriptions that execute in a victim's browser.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-8726?
CVE-2025-8726 has been classified as a moderate severity vulnerability due to its potential for Cross-Site Scripting attacks.
Who is affected by CVE-2025-8726?
CVE-2025-8726 affects users of the WP Photo Album Plus plugin for WordPress in all versions up to and including 9.0.11.006.
How do I fix CVE-2025-8726?
To fix CVE-2025-8726, update the WP Photo Album Plus plugin to the latest version that has addressed this vulnerability.
What type of vulnerability is CVE-2025-8726?
CVE-2025-8726 is a Cross-Site Scripting (XSS) vulnerability caused by insufficient input sanitization and output escaping.
Can authenticated users exploit CVE-2025-8726?
Yes, authenticated attackers can exploit CVE-2025-8726 to execute malicious scripts due to the vulnerability in the wppa_user_upload function.