WP Photo Album Plus

WP Photo Album Plus has 31 disclosed vulnerabilities in the WordSec catalog, reported between 2008 and 2026; all 31 are fixed as of September 2026. Their average CVSS score is 6.7, and the most serious one scores 10.0 out of 10. Severity breakdown: 4 critical and 9 high. 2026 was the busiest year with 14 disclosures.

The most common weakness is Cross-Site Scripting, behind 15 of the records (48%). Other recurring categories include SQL Injection, Authorization Bypass Through User-Controlled Key.

Every one of the 31 issues recorded for WP Photo Album Plus has a vendor fix available, so running the current release closes all known holes.

24 independent researchers contributed these findings, most of them (5) reported by stealthcopter. WP Photo Album Plus is installed on roughly 10,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.

01234567891003.02.2010Today25.02.20089.8WP Photo Album Plus <= 1.1 - SQL Injection CVSS 9.8 · 25.02.200806.05.20136.1WP Photo Album Plus < 5.0.3 - Cross-Site Scripting CVSS 6.1 · 06.05.201317.09.20146.4WP Photo Album Plus <= 5.4.7 - Stored Cross-Site Scripting CVSS 6.4 · 17.09.201406.11.20146.1WP Photo Album Plus <= 5.4.17 - Reflected Cross-Site Scripting CVSS 6.1 · 06.11.201420.05.20157.1WP Photo Album Plus < 6.1.3 - Cross-Site Scripting CVSS 7.1 · 20.05.201502.01.20227.2WP Photo Album Plus <= 8.0.10 - Stored Cross-Site Scripting CVSS 7.2 · 02.01.202205.12.20236.1WP Photo Album Plus <= 8.5.02.005 - Cross-Site Scripting CVSS 6.1 · 05.12.20235.3WP Photo Album Plus <= 8.5.02.005 - Insecure Direct Object Reference CVSS 5.3 · 05.12.20235.3WP Photo Album Plus <= 8.5.02.005 - IP Spoofing CVSS 5.3 · 05.12.202305.04.20249.9WP Photo Album Plus <= 8.6.03.004 - Authenticated (Subscriber+) Arbitrary File Upload CVSS 9.9 · 05.04.202407.05.202410.0WP Photo Album Plus <= 8.7.01.001 - Unauthenticated Arbitrary File Upload CVSS 10.0 · 07.05.202423.05.20246.5WP Photo Album Plus <= 8.7.02.003 - Unauthenticated Arbitrary Shortcode Execution CVSS 6.5 · 23.05.202428.06.20246.1WP Photo Album Plus <= 8.8.00.002 - Reflected Cross-Site Scripting CVSS 6.1 · 28.06.202411.07.20246.4WP Photo Album Plus <= 8.8.02.002 - Authenticated (Subscriber+) Stored Cross-Site Scripting CVSS 6.4 · 11.07.202416.10.20246.1Wordpress Photo Album Plus <= 8.8.05.003 - Reflected Cross-Site Scripting CVSS 6.1 · 16.10.202410.11.20247.3WP Photo Album Plus <= 8.8.08.007 - Unauthenticated Arbitrary Shortcode Execution via getshortcodedrenderedfenodelay CVSS 7.3 · 10.11.202403.10.20255.4WP Photo Album Plus <= 9.0.11.006 - Authenticated (Subscriber+) Stored Cross-Site Scripting via wppa_user_upload CVSS 5.4 · 03.10.202506.01.20267.1WP Photo Album Plus <= 9.1.05.008 - Reflected Cross-Site Scripting CVSS 7.1 · 06.01.202613.04.20267.5WP Photo Album Plus <= 9.1.08.001 - Unauthenticated SQL Injection CVSS 7.5 · 13.04.202611.06.20267.5WP Photo Album Plus < 9.1.11.001 - Unauthenticated SQL Injection CVSS 7.5 · 11.06.202617.06.20267.5WP Photo Album Plus <= 9.1.13.005 - Unauthenticated SQL Injection CVSS 7.5 · 17.06.202630.06.20267.2WP Photo Album Plus <= 9.2.02.004 - Unauthenticated Stored Cross-Site Scripting CVSS 7.2 · 30.06.20266.4WP Photo Album Plus <= 9.1.13.005 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'subtext' Shortcode Attribute CVSS 6.4 · 30.06.202628.07.20264.9WP Photo Album Plus <= 9.2.04.002 - Authenticated (Administrator+) SQL Injection via 'table' Parameter CVSS 4.9 · 28.07.202603.08.20265.3Photo Album Plus <= 9.2.07.1 - Unauthenticated Export ZIP File Deletion CVSS 5.3 · 03.08.202610.08.20266.1Photo Album Plus <= 9.2.07.1 - Reflected Cross-Site Scripting CVSS 6.1 · 10.08.20264.3Photo Album Plus <= 9.2.09.1 - Missing Authorization CVSS 4.3 · 10.08.20269.1Photo Album Plus <= 9.2.07.1 - Arbitrary File Deletion to Unauthenticated Arbitrary ZIP File Deletion CVSS 9.1 · 10.08.202613.08.20266.4WP Photo Album Plus < 9.2.04.003 - Authenticated (Subscriber+) Stored Cross-Site Scripting CVSS 6.4 · 13.08.202614.08.20265.3WP Photo Album Plus < 9.2.07.002 - Missing Authorization CVSS 5.3 · 14.08.202610.09.20267.2WP Photo Album Plus <= 9.2.08.003 - Unauthenticated Stored Cross-Site Scripting CVSS 7.2 · 10.09.2026

Strategic Overview

Avg CVSSMedium
6.7/ 10
Patch Coverage100%
Open

0

Fixed

31

Get automatic notifications for all WP Photo Album Plus vulnerabilities before they are exploited.

Highest severity on recordCVSS 10.0CVE-2024-31377

WP Photo Album Plus <= 8.7.01.001 - Unauthenticated Arbitrary File Upload

Read the full analysis

Vulnerability Records

31 records
2026-09-10 14:45CVE-2026-18579
7.2
High
Jonah Burgess (CryptoCat)Yes
2026-08-14 00:00CVE-2026-18049
5.3
Medium
Erwan LRYes
2026-08-13 00:00CVE-2026-14922
6.4
Medium
Sai Praneeth KotiYes
2026-08-10 00:00CVE-2026-17013
6.1
Medium
Muni Nitish Kumar YaddalaYes
2026-08-10 00:00CVE-2026-18962
4.3
Medium
Farid NarimanovYes
2026-08-10 00:00CVE-2026-18048
9.1
Critical
Erwan LRYes
2026-08-03 00:00CVE-2026-17014
5.3
Medium
Vaibhav NarkhedeYes
2026-07-28 13:34CVE-2026-15344
4.9
Medium
Wordfence PRISMYes
2026-06-30 21:28CVE-2026-10095
6.4
Medium
Muhammad Yudha - DJYes
2026-06-30 00:00CVE-2026-57675
7.2
High
Nguyen Ba KhanhYes
Showing 1–10 of 31 reports
Plugin Profile
Latestv9.3.00.003

WP Photo Album Plus

Jacob N. Breetvelt

Author

Jacob N. Breetvelt

4.7(199)
94/100
Last Updated
2026-09-11 (2d ago)
Active Installs
10,000+
Downloads
3,474,570
Requires WP
6.9+
Requires PHP
5.5+
Tested up to
WP 7.1
Created
2010-02-03 (17y ago)

This plugin is more than just a photo album plugin, it is a complete, highly customizable multimedia content management and display system. Features: Any number of albums that contain any type of multimedia file as well as sub albums. Full control over the display sizes, responsive as well as static. Full control over links from any type of image. Full control over metadata: exif, iptc can be used by keywords in item descriptions. Up to 10 custom defined meta data fields, for albums and for media items. Front-end uploads. Bulk imports. Built-in lightbox overlay system. Built-in Google Maps to display maps based on the photo gpx exif data. Built-in search functions on a.o. keywords and tags. A customizable rating system. Commenting system. Moderate user uploads and comments. Configurable email notification system. 20 widgets a.o. upload, slideshow, photo of the day, top rated and commented items and many more. Supports Cloudinary cloud storage service. Supports Fotomoto print service. Required maintenace is fully executed by background processes (cron jobs). Extended error/event logging system. Extended documentation site: https://wppa.nl/ Plugin Admin Features: You can find the plugin admin section under Menu Photo Albums on the admin screen. Albums: Create and manage Albums. Upload: To upload photos to an album you created. Import: To bulk import items to an album that are previously been ftp’d. Moderate: Change status of pending Export: To export albums Settings: To control the various settings to customize your needs. photo of the day widget settings Help & Info: Credits and link to the documentation site Translations: Dutch translation by OpaJaap himself (Opa Jaap’s Weblog) Slovak translation by Branco Radenovich (WebHostingGeeks.com) Polish translation by Maciej Matysiak Ukranian translation by Michael Yunat (http://getvoip.com) Italian translation by Giacomo Mazzullo (http://gidibao.net & http://charmingpress.com) German translation by Stefan Eggers Portuguese translation by Eric Sornoso (https://Mealfan.com) Privacy Policy When you leave a comment on a photo or other media item on this site, we send your name, email address, IP address and comment text to the server. When you enter a rating on a photo or other media item on this site, we send your (login)name or IP address and your rating to the server. When you upload a photo or other media item on this site, we send your name to the server. If the photo contains EXIF or IPTC data, this data may – dependant of the configuration – be saved on the server. If the photo contains GPX location data, this data will be saved on the server. If visit the site, the pages you visit, the photos you watch and your IP address will be saved on the server for statistical purposes in your session information. This information will be anonimized after one hour and removed after 24 hours. About and Credits WP Photo Album Plus is extended with many new features and is maintained by J.N. Breetvelt, ( http://www.opajaap.nl/ ) a.k.a. OpaJaap Thanx to R.J. Kaplan for WP Photo Album 1.5.1, the basis of this plugin. Licence WP Photo Album is released under the GNU GPL licence. ( http://www.gnu.org/copyleft/gpl.html )

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C