{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/wp-photo-album-plus--9.2.08.003/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:wppa:wp_photo_album_plus:*:*:*:*:*:wordpress:*:*"],"_cs_cves":[{"cvss":7.2,"id":"CVE-2026-18579"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["WP Photo Album Plus (\u003c= 9.2.08.003)"],"_cs_severities":["high"],"_cs_tags":["web-application","xss","wordpress"],"_cs_type":"advisory","_cs_vendors":["WordPress"],"content_html":"\u003cp\u003eThe WP Photo Album Plus plugin for WordPress contains a Stored Cross-Site Scripting (XSS) vulnerability affecting all versions up to and including 9.2.08.003. The vulnerability originates from insufficient sanitization of the HTTP_X_FORWARDED_FOR header. Specifically, the plugin's code handles the 'getshortcodedrenderedfenodelay' action by executing a nonce check; however, the failure path of this check does not terminate the request. Instead, it triggers the 'wppa_log' function, which writes the attacker-supplied header value to disk without proper escaping.\u003c/p\u003e\n\u003cp\u003eThis flaw allows unauthenticated attackers to interact with the 'wp_ajax_nopriv_wppa' endpoint to inject arbitrary JavaScript. When an administrator or privileged user views the plugin logs, the stored malicious script executes within their session context. This vulnerability is critical for WordPress administrators as it provides a pathway for session hijacking or unauthorized administrative actions.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker identifies the target WordPress site running a vulnerable version of the WP Photo Album Plus plugin.\u003c/li\u003e\n\u003cli\u003eAttacker crafts an HTTP request containing a malicious payload within the 'X-Forwarded-For' header.\u003c/li\u003e\n\u003cli\u003eAttacker sends a POST request to the 'wp_ajax_nopriv_wppa' endpoint.\u003c/li\u003e\n\u003cli\u003eThe plugin triggers the 'getshortcodedrenderedfenodelay' action, which intentionally fails a nonce validation.\u003c/li\u003e\n\u003cli\u003eThe plugin code branches into the failed-nonce logging path instead of discarding the request.\u003c/li\u003e\n\u003cli\u003eThe 'wppa_log' function writes the unescaped 'X-Forwarded-For' value to the local log file.\u003c/li\u003e\n\u003cli\u003eA site administrator navigates to the plugin's administrative log dashboard.\u003c/li\u003e\n\u003cli\u003eThe stored malicious script executes in the administrator's browser, potentially leading to account compromise or further system exploitation.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to execute arbitrary JavaScript in the context of an administrator's browser session. This can result in unauthorized administrative modifications, account takeovers, or the redirection of site traffic. Given that this vulnerability targets site logging mechanisms, it represents a significant risk to the integrity of administrative interfaces in WordPress environments.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade the WP Photo Album Plus plugin to the latest available version beyond 9.2.08.003 immediately to incorporate input sanitization patches.\u003c/li\u003e\n\u003cli\u003eImplement a Web Application Firewall (WAF) rule to inspect and block X-Forwarded-For headers containing common JavaScript characters such as '\u0026lt;', '\u0026gt;', 'script', and 'onerror'.\u003c/li\u003e\n\u003cli\u003eAudit administrative activity logs for anomalous entries containing HTML or script tags.\u003c/li\u003e\n\u003cli\u003eDeploy the suggested WAF rule to detect and block suspicious HTTP requests targeting the wp_ajax_nopriv_wppa endpoint.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-11T05:11:57Z","date_published":"2026-09-11T05:11:57Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-18579-xss/","summary":"An unauthenticated stored XSS vulnerability in WP Photo Album Plus versions 9.2.08.003 and earlier allows attackers to inject malicious scripts via the HTTP_X_FORWARDED_FOR header, which is logged without sanitization.","title":"Stored XSS Vulnerability in WP Photo Album Plus Plugin","url":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-18579-xss/"}],"language":"en","title":"CraftedSignal Threat Feed - WP Photo Album Plus (\u003c= 9.2.08.003)","version":"https://jsonfeed.org/version/1.1"}