CVE-2026-57675: WordPress WP Photo Album Plus plugin <= 9.2.02.004 - Cross Site Scripting (XSS) vulnerability
Published Jul 2, 2026
·Updated
Unauthenticated Cross Site Scripting (XSS) in WP Photo Album Plus <= 9.2.02.004 versions.
Affected Software
1 affected component
WordPress WP Photo Album Plus<=9.2.02.004
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress WP Photo Album Plus pluginto a version that resolves this vulnerability.Fixed in 9.2.03.001
Event History
Jul 2, 2026
CVE Published
via MITRE·11:15 AM
Data Sourced
via MITRE·11:15 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·12:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-57675?
CVE-2026-57675 has a severity rating of 7.1, classifying it as high risk.
2
What type of vulnerability is CVE-2026-57675?
CVE-2026-57675 is an unauthenticated Cross Site Scripting (XSS) vulnerability.
3
How do I fix CVE-2026-57675?
To fix CVE-2026-57675, update the WP Photo Album Plus plugin to version 9.2.02.005 or later.
4
Who is affected by CVE-2026-57675?
CVE-2026-57675 affects users of the WP Photo Album Plus plugin version 9.2.02.004 and earlier.
5
When was CVE-2026-57675 published?
CVE-2026-57675 was published on July 2, 2026.