CVE-2026-17013
Deferred Deferred - Pending Action

WP Photo Album Plus Reflected XSS Vulnerability

Vulnerability report for CVE-2026-17013, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-12

Last updated on: 2026-08-26

Assigner: WPScan

Description

The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not sanitise and escape a parameter before reflecting it into an inline script block, which could allow unauthenticated attackers to perform Reflected Cross-Site Scripting attacks against anyone who is tricked into opening a crafted link to a page displaying one of its galleries.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-12
Last Modified
2026-08-26
Generated
2026-09-01
AI Q&A
2026-08-12
EPSS Evaluated
2026-08-31
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
wp_photo_album_plus wp_photo_album_plus to 9.2.07.002 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-287 When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a Reflected Cross-Site Scripting (XSS) vulnerability in the WP Photo Album Plus WordPress plugin before version 9.2.07.002. The plugin does not properly sanitize and escape the 'lbstart' parameter before reflecting it into an inline script block. This allows unauthenticated attackers to inject malicious JavaScript code via a crafted link.

Detection Guidance

To detect this vulnerability, check the installed version of the WP Photo Album Plus plugin. If it is below 9.2.07.002, the system is vulnerable. You can verify the version via WordPress admin panel or by inspecting plugin files.

Impact Analysis

If you are a user of the affected plugin version, attackers could trick you into clicking a malicious link. This could lead to execution of arbitrary JavaScript in your browser, potentially stealing session cookies, performing actions on your behalf, or redirecting you to phishing sites.

Compliance Impact

This vulnerability could lead to unauthorized access to user data, which may violate GDPR (data protection) and HIPAA (health data privacy) requirements. Organizations using the vulnerable plugin may face compliance violations, legal penalties, and reputational damage if user data is compromised.

Mitigation Strategies

Immediately update the WP Photo Album Plus plugin to version 9.2.07.002 or later. If updating is not possible, consider disabling the plugin until an update is applied to prevent exploitation.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-17013. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart