{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/wp-photo-album-plus--9.3.03.002/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:wordpress:wp_photo_album_plus:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.2,"id":"CVE-2026-96278"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["WP Photo Album Plus (\u003c= 9.3.03.002)"],"_cs_severities":["high"],"_cs_tags":["xss","web-vulnerability"],"_cs_type":"advisory","_cs_vendors":["WordPress"],"content_html":"\u003cp\u003eThe WP Photo Album Plus plugin for WordPress contains a stored Cross-Site Scripting (XSS) vulnerability affecting all versions up to and including 9.3.03.002. The vulnerability stems from improper sanitization of the REQUEST_URI session history and subsequent insecure output handling. While the plugin utilizes esc_url_raw(), this function fails to provide adequate protection as it retains HTML entities. The internal function wppaEntityDecode() inadvertently reverses this by converting entities back into active HTML tags. These tags are then processed by the jQuery('#wppa-modal-container').html() function, resulting in the execution of arbitrary JavaScript within the context of the user's browser. This flaw allows unauthenticated remote attackers to execute scripts in the sessions of unsuspecting users, potentially leading to session hijacking, administrative action spoofing, or unauthorized content modification.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker identifies a target WordPress site running a vulnerable version of the WP Photo Album Plus plugin.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a malicious HTTP request containing HTML entities designed to bypass esc_url_raw() filtering.\u003c/li\u003e\n\u003cli\u003eThe malicious payload is injected into the REQUEST_URI, which the plugin captures as part of its session history logging mechanism.\u003c/li\u003e\n\u003cli\u003eThe application stores the unauthenticated user's malicious REQUEST_URI in the backend database.\u003c/li\u003e\n\u003cli\u003eA victim user (such as an administrator) navigates to a page within the plugin that displays the session history.\u003c/li\u003e\n\u003cli\u003eThe plugin retrieves the stored malicious URI and passes it through the flawed wppaEntityDecode() function.\u003c/li\u003e\n\u003cli\u003eThe decoded payload is rendered into the DOM via the jQuery('#wppa-modal-container').html() sink.\u003c/li\u003e\n\u003cli\u003eThe victim's browser executes the injected script, allowing the attacker to perform actions as the victim.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to execute arbitrary web scripts in the browser of any user viewing the affected page. In WordPress environments, this commonly leads to full administrative account takeover if an administrator views the injected content, ultimately allowing for complete site compromise, data exfiltration, or defacement.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade the WP Photo Album Plus plugin to the latest version, ensuring all security patches associated with CVE-2026-96278 are applied immediately.\u003c/li\u003e\n\u003cli\u003eImplement a Web Application Firewall (WAF) rule to inspect and block requests containing suspicious HTML patterns or script tags in the URI request parameters.\u003c/li\u003e\n\u003cli\u003eMonitor web access logs for anomalous requests containing URL-encoded characters or common XSS payloads directed at the WordPress site.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-10-10T09:51:48Z","date_published":"2026-10-10T09:51:48Z","id":"https://feed.craftedsignal.io/briefs/2026-10-wppa-xss/","summary":"An unauthenticated stored XSS vulnerability in WP Photo Album Plus \u003c= 9.3.03.002 allows attackers to inject malicious scripts via REQUEST_URI session history due to insecure output rendering.","title":"Stored Cross-Site Scripting in WP Photo Album Plus Plugin","url":"https://feed.craftedsignal.io/briefs/2026-10-wppa-xss/"}],"language":"en","title":"CraftedSignal Threat Feed - WP Photo Album Plus (\u003c= 9.3.03.002)","version":"https://jsonfeed.org/version/1.1"}