Stored Cross-Site Scripting in WP Photo Album Plus Plugin
An unauthenticated stored XSS vulnerability in WP Photo Album Plus <= 9.3.03.002 allows attackers to inject malicious scripts via REQUEST_URI session history due to insecure output rendering.
CVE search metadata
CVE search record: CVE-2026-96278. Severity: high. CVSS: 7.2. KEV: no. Product: WP Photo Album Plus (<= 9.3.03.002). Brief: Stored Cross-Site Scripting in WP Photo Album Plus Plugin. Brief link: https://feed.craftedsignal.io/briefs/2026-10-wppa-xss/
The WP Photo Album Plus plugin for WordPress contains a stored Cross-Site Scripting (XSS) vulnerability affecting all versions up to and including 9.3.03.002. The vulnerability stems from improper sanitization of the REQUEST_URI session history and subsequent insecure output handling. While the plugin utilizes esc_url_raw(), this function fails to provide adequate protection as it retains HTML entities. The internal function wppaEntityDecode() inadvertently reverses this by converting entities back into active HTML tags. These tags are then processed by the jQuery('#wppa-modal-container').html() function, resulting in the execution of arbitrary JavaScript within the context of the user's browser. This flaw allows unauthenticated remote attackers to execute scripts in the sessions of unsuspecting users, potentially leading to session hijacking, administrative action spoofing, or unauthorized content modification.
Attack Chain
- Attacker identifies a target WordPress site running a vulnerable version of the WP Photo Album Plus plugin.
- Attacker crafts a malicious HTTP request containing HTML entities designed to bypass esc_url_raw() filtering.
- The malicious payload is injected into the REQUEST_URI, which the plugin captures as part of its session history logging mechanism.
- The application stores the unauthenticated user's malicious REQUEST_URI in the backend database.
- A victim user (such as an administrator) navigates to a page within the plugin that displays the session history.
- The plugin retrieves the stored malicious URI and passes it through the flawed wppaEntityDecode() function.
- The decoded payload is rendered into the DOM via the jQuery('#wppa-modal-container').html() sink.
- The victim's browser executes the injected script, allowing the attacker to perform actions as the victim.
Impact
Successful exploitation allows unauthenticated attackers to execute arbitrary web scripts in the browser of any user viewing the affected page. In WordPress environments, this commonly leads to full administrative account takeover if an administrator views the injected content, ultimately allowing for complete site compromise, data exfiltration, or defacement.
Recommendation
- Upgrade the WP Photo Album Plus plugin to the latest version, ensuring all security patches associated with CVE-2026-96278 are applied immediately.
- Implement a Web Application Firewall (WAF) rule to inspect and block requests containing suspicious HTML patterns or script tags in the URI request parameters.
- Monitor web access logs for anomalous requests containing URL-encoded characters or common XSS payloads directed at the WordPress site.
Immediate actions
Upgrade WP Photo Album Plus to a patched version.
Mitigations
Deploy WAF rules to sanitize URI requests containing HTML tags.
CVE-2026-96278