CVE-2026-17013: WP Photo Album Plus < 9.2.07.002 - Reflected XSS via lbstart
The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not sanitise and escape a parameter before reflecting it into an inline script block, which could allow unauthenticated attackers to perform Reflected Cross-Site Scripting attacks against anyone who is tricked into opening a crafted link to a page displaying one of its galleries.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-17013?
CVE-2026-17013 has a risk rating of 35, indicating it poses a moderate threat due to potential Reflected Cross-Site Scripting vulnerabilities.
How do I fix CVE-2026-17013?
To fix CVE-2026-17013, update the WP Photo Album Plus plugin to version 9.2.07.002 or later.
What is the impact of CVE-2026-17013?
The impact of CVE-2026-17013 allows unauthenticated attackers to perform Reflected Cross-Site Scripting attacks against users.
Who is affected by CVE-2026-17013?
CVE-2026-17013 affects users of the WP Photo Album Plus WordPress plugin prior to version 9.2.07.002.
What type of vulnerability is CVE-2026-17013?
CVE-2026-17013 is classified as a Cross-Site Scripting (XSS) vulnerability.