Wppa
Wppa WP Photo Album Plus: vulnerabilidades y CVE
Wppa WP Photo Album Plus tiene 28 vulnerabilidades publicadas, 16 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE28
Últimos 12 meses16
Críticas3
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-102386 | Media (6.5) | 0.21% | — | 30 sept 2026 | Subscriber Cross Site Scripting (XSS) in WP Photo Album Plus <= 9.3.02.003 versions. |
| CVE-2026-93774 | Alta (7.1) | 0.19% | — | 23 sept 2026 | Unauthenticated Cross Site Scripting (XSS) in WP Photo Album Plus <= 9.3.02.002 versions. |
| CVE-2026-87909 | Alta (7.5) | 0.91% | — | 19 sept 2026 | The WP Photo Album Plus plugin for WordPress is vulnerable to Remote Code Execution in all versions via the wppa_image_magick function. This is due to insufficient sanitization of the multipart upload filename before… |
| CVE-2026-18579 | Alta (7.2) | 0.29% | — | 11 sept 2026 | The WP Photo Album Plus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'HTTP_X_FORWARDED_FOR' parameter in all versions up to, and including, 9.2.08.003 due to insufficient input sanitization… |
| CVE-2026-18962 | Media (4.3) | 0.25% | — | 12 ago 2026 | The WP Photo Album Plus WordPress plugin before 9.2.09.002 does not check that the current user is allowed to upload into the album they target when it processes a front-end upload, allowing any authenticated user, such… |
| CVE-2026-18049 | Alta (7.5) | 0.43% | — | 12 ago 2026 | The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not perform any capability or nonce check on one of its public endpoint actions and builds an option name from a client-supplied value without restricting… |
| CVE-2026-17013 | Media (6.1) | 0.26% | — | 12 ago 2026 | The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not sanitise and escape a parameter before reflecting it into an inline script block, which could allow unauthenticated attackers to perform Reflected… |
| CVE-2026-17014 | Media (5.3) | 0.32% | — | 9 ago 2026 | The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not perform any capability or nonce check on one of its public REST endpoint actions, allowing unauthenticated users to delete the generated album export… |
| CVE-2026-14922 | Media (6.1) | 0.25% | — | 31 jul 2026 | WP Photo Album Plus is vulnerable to stored Cross-Site Scripting in all versions up to, and including, 9.2.03.001 through a decode-after-sanitize (double-encoding) flaw in the photo-comment pipeline. On write,… |
| CVE-2026-15344 | Media (4.9) | 0.60% | — | 29 jul 2026 | The WP Photo Album Plus plugin for WordPress is vulnerable to generic SQL Injection via the 'table' parameter in all versions up to, and including, 9.2.04.002 due to insufficient escaping on the user supplied parameter… |
| CVE-2026-57675 | Alta (7.1) | 0.25% | — | 2 jul 2026 | Unauthenticated Cross Site Scripting (XSS) in WP Photo Album Plus <= 9.2.02.004 versions. |
| CVE-2026-10095 | Media (6.4) | 0.42% | — | 1 jul 2026 | The WP Photo Album Plus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'subtext' parameter in all versions up to, and including, 9.1.13.005 due to insufficient input sanitization and output… |
| CVE-2026-54829 | Alta (7.5) | 0.32% | — | 25 jun 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Jacob N. Breetvelt WP Photo Album Plus allows Blind SQL Injection. This issue affects WP Photo Album Plus: from n/a… |
| CVE-2026-39511 | Crítica (9.3) | 0.40% | — | 15 jun 2026 | Unauthenticated SQL Injection in WP Photo Album Plus <= 9.1.08.001 versions. |
| CVE-2026-6379 | Alta (8.6) | 0.45% | — | 18 may 2026 | The WP Photo Album Plus WordPress plugin before 9.1.11.001 does not properly sanitize and escape a parameter before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks. |
| CVE-2025-14835 | Alta (7.1) | 0.28% | — | 7 ene 2026 | The WP Photo Album Plus plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘shortcode’ parameter in all versions up to, and including, 9.1.05.008 due to insufficient input sanitization and… |
| CVE-2025-8726 | Media (5.4) | 0.21% | — | 4 oct 2025 | The WP Photo Album Plus plugin for WordPress is vulnerable to Cross-Site Scripting in all versions up to, and including, 9.0.11.006 due to insufficient input sanitization and output escaping in the wppa_user_upload… |
| CVE-2024-10958 | Alta (7.3) | 1.6% | — | 10 nov 2024 | The The WP Photo Album Plus plugin for WordPress is vulnerable to arbitrary shortcode execution via getshortcodedrenderedfenodelay AJAX action in all versions up to, and including, 8.8.08.007 . This is due to the… |
| CVE-2024-9951 | Media (6.1) | 0.32% | — | 17 oct 2024 | The WP Photo Album Plus plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wppa-tab' parameter in all versions up to, and including, 8.8.05.003 due to insufficient input sanitization and… |
| CVE-2024-37416 | Media (6.1) | 0.33% | — | 22 jul 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in J.N. Breetvelt a.K.A. OpaJaap WP Photo Album Plus allows Reflected XSS.This issue affects WP Photo Album Plus:… |
| CVE-2024-38713 | Media (6.5) | 0.27% | — | 20 jul 2024 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in J.N. Breetvelt a.K.A. OpaJaap WP Photo Album Plus allows Stored XSS.This issue affects WP Photo Album Plus:… |
| CVE-2023-49774 | Media (5.3) | 0.31% | — | 4 jun 2024 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in J.N. Breetvelt a.K.A. OpaJaap WP Photo Album Plus allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WP Photo… |
| CVE-2024-4037 | Alta (7.3) | 0.48% | — | 24 may 2024 | The WP Photo Album Plus plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 8.7.02.003. This is due to the plugin allowing unauthenticated users to execute an action… |
| CVE-2024-31377 | Crítica (10) | 0.54% | — | 14 may 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in J.N. Breetvelt a.K.A. OpaJaap WP Photo Album Plus.This issue affects WP Photo Album Plus: from n/a through 8.7.01.001. |
| CVE-2024-31286 | Crítica (9.9) | 0.86% | — | 7 abr 2024 | Unrestricted Upload of File with Dangerous Type vulnerability in J.N. Breetvelt a.K.A. OpaJaap WP Photo Album Plus.This issue affects WP Photo Album Plus: from n/a before 8.6.03.005. |
| CVE-2023-49812 | Alta (7.5) | 0.53% | — | 19 dic 2023 | Authorization Bypass Through User-Controlled Key vulnerability in J.N. Breetvelt a.K.A. OpaJaap WP Photo Album Plus.This issue affects WP Photo Album Plus: from n/a through 8.5.02.005. |
| CVE-2023-49813 | Media (6.1) | 0.39% | — | 14 dic 2023 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in J.N. Breetvelt a.K.A. OpaJaap WP Photo Album Plus allows Stored XSS.This issue affects WP Photo Album Plus: from n/a… |
| CVE-2021-25115 | Media (6.4) | 0.68% | — | 14 feb 2022 | The WP Photo Album Plus WordPress plugin before 8.0.10 was vulnerable to Stored Cross-Site Scripting (XSS). Error log content was handled improperly, therefore any user, even unauthenticated, could cause arbitrary… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.