CPE
An unauthenticated stored XSS vulnerability in WP Photo Album Plus versions 9.2.08.003 and earlier allows attackers to inject malicious scripts via the HTTP_X_FORWARDED_FOR header, which is logged without sanitization.