WP Photo Album Plus

Explore WP Photo Album Plus vulnerabilities across all versions. Currently tracking 24 known vulnerabilities, including severity, impact, and patch status.

01234567891003.02.2010Today25.02.20089.8WP Photo Album Plus <= 1.1 - SQL Injection CVSS 9.8 · 25.02.200806.05.20136.1WP Photo Album Plus < 5.0.3 - Cross-Site Scripting CVSS 6.1 · 06.05.201317.09.20146.4WP Photo Album Plus <= 5.4.7 - Stored Cross-Site Scripting CVSS 6.4 · 17.09.201406.11.20146.1WP Photo Album Plus <= 5.4.17 - Reflected Cross-Site Scripting CVSS 6.1 · 06.11.201420.05.20157.1WP Photo Album Plus < 6.1.3 - Cross-Site Scripting CVSS 7.1 · 20.05.201502.01.20227.2WP Photo Album Plus <= 8.0.10 - Stored Cross-Site Scripting CVSS 7.2 · 02.01.202205.12.20235.3WP Photo Album Plus <= 8.5.02.005 - Insecure Direct Object Reference CVSS 5.3 · 05.12.20235.3WP Photo Album Plus <= 8.5.02.005 - IP Spoofing CVSS 5.3 · 05.12.20236.1WP Photo Album Plus <= 8.5.02.005 - Cross-Site Scripting CVSS 6.1 · 05.12.202305.04.20249.9WP Photo Album Plus <= 8.6.03.004 - Authenticated (Subscriber+) Arbitrary File Upload CVSS 9.9 · 05.04.202407.05.202410.0WP Photo Album Plus <= 8.7.01.001 - Unauthenticated Arbitrary File Upload CVSS 10.0 · 07.05.202423.05.20246.5WP Photo Album Plus <= 8.7.02.003 - Unauthenticated Arbitrary Shortcode Execution CVSS 6.5 · 23.05.202428.06.20246.1WP Photo Album Plus <= 8.8.00.002 - Reflected Cross-Site Scripting CVSS 6.1 · 28.06.202411.07.20246.4WP Photo Album Plus <= 8.8.02.002 - Authenticated (Subscriber+) Stored Cross-Site Scripting CVSS 6.4 · 11.07.202416.10.20246.1Wordpress Photo Album Plus <= 8.8.05.003 - Reflected Cross-Site Scripting CVSS 6.1 · 16.10.202410.11.20247.3WP Photo Album Plus <= 8.8.08.007 - Unauthenticated Arbitrary Shortcode Execution via getshortcodedrenderedfenodelay CVSS 7.3 · 10.11.202403.10.20255.4WP Photo Album Plus <= 9.0.11.006 - Authenticated (Subscriber+) Stored Cross-Site Scripting via wppa_user_upload CVSS 5.4 · 03.10.202506.01.20267.1WP Photo Album Plus <= 9.1.05.008 - Reflected Cross-Site Scripting CVSS 7.1 · 06.01.202613.04.20267.5WP Photo Album Plus <= 9.1.08.001 - Unauthenticated SQL Injection CVSS 7.5 · 13.04.202611.06.20267.5WP Photo Album Plus < 9.1.11.001 - Unauthenticated SQL Injection CVSS 7.5 · 11.06.202617.06.20267.5WP Photo Album Plus <= 9.1.13.005 - Unauthenticated SQL Injection CVSS 7.5 · 17.06.202630.06.20267.2WP Photo Album Plus <= 9.2.02.004 - Unauthenticated Stored Cross-Site Scripting CVSS 7.2 · 30.06.20266.4WP Photo Album Plus <= 9.1.13.005 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'subtext' Shortcode Attribute CVSS 6.4 · 30.06.202628.07.20264.9WP Photo Album Plus <= 9.2.04.002 - Authenticated (Administrator+) SQL Injection via 'table' Parameter CVSS 4.9 · 28.07.2026

Strategic Overview

Avg CVSSMedium
6.9/ 10
Patch Coverage100%
Open

0

Fixed

24

Get automatic notifications for all WP Photo Album Plus vulnerabilities before they are exploited.

Vulnerability Records

24 records
2026-07-28 13:34CVE-2026-15344
4.9
Medium
Wordfence PRISMYes
2026-06-30 21:28CVE-2026-10095
6.4
Medium
Muhammad Yudha - DJYes
2026-06-30 00:00CVE-2026-57675
7.2
High
Nguyen Ba KhanhYes
2026-06-17 00:00CVE-2026-54829
7.5
High
darooYes
2026-06-11 00:00CVE-2026-6379
7.5
High
Daniel Púa - devploitYes
2026-04-13 00:00CVE-2026-39511
7.5
High
Martín MartínYes
2026-01-06 16:37CVE-2025-14835
7.1
High
Muhammad Yudha - DJYes
2025-10-03 14:09CVE-2025-8726
5.4
Medium
zer0gh0stYes
2024-11-10 00:18CVE-2024-10958
7.3
High
Arkadiusz HydzikYes
2024-10-16 00:00CVE-2024-9951
6.1
Medium
Noah Stead (TurtleBurg)Yes
Showing 1–10 of 24 reports
Plugin Profile
Latestv9.2.07.002

WP Photo Album Plus

Jacob N. Breetvelt

Author

Jacob N. Breetvelt

4.7(199)
94/100
Last Updated
2026-07-28 (2d ago)
Active Installs
10,000+
Downloads
3,449,669
Requires WP
6.9+
Requires PHP
5.5+
Tested up to
WP 7.0.2
Created
2010-02-03 (17y ago)

This plugin is more than just a photo album plugin, it is a complete, highly customizable multimedia content management and display system. Features: Any number of albums that contain any type of multimedia file as well as sub albums. Full control over the display sizes, responsive as well as static. Full control over links from any type of image. Full control over metadata: exif, iptc can be used by keywords in item descriptions. Up to 10 custom defined meta data fields, for albums and for media items. Front-end uploads. Bulk imports. Built-in lightbox overlay system. Built-in Google Maps to display maps based on the photo gpx exif data. Built-in search functions on a.o. keywords and tags. A customizable rating system. Commenting system. Moderate user uploads and comments. Configurable email notification system. 20 widgets a.o. upload, slideshow, photo of the day, top rated and commented items and many more. Supports Cloudinary cloud storage service. Supports Fotomoto print service. Required maintenace is fully executed by background processes (cron jobs). Extended error/event logging system. Extended documentation site: https://wppa.nl/ Plugin Admin Features: You can find the plugin admin section under Menu Photo Albums on the admin screen. Albums: Create and manage Albums. Upload: To upload photos to an album you created. Import: To bulk import items to an album that are previously been ftp’d. Moderate: Change status of pending Export: To export albums Settings: To control the various settings to customize your needs. photo of the day widget settings Help & Info: Credits and link to the documentation site Translations: Dutch translation by OpaJaap himself (Opa Jaap’s Weblog) Slovak translation by Branco Radenovich (WebHostingGeeks.com) Polish translation by Maciej Matysiak Ukranian translation by Michael Yunat (http://getvoip.com) Italian translation by Giacomo Mazzullo (http://gidibao.net & http://charmingpress.com) German translation by Stefan Eggers Portuguese translation by Eric Sornoso (https://Mealfan.com) Privacy Policy When you leave a comment on a photo or other media item on this site, we send your name, email address, IP address and comment text to the server. When you enter a rating on a photo or other media item on this site, we send your (login)name or IP address and your rating to the server. When you upload a photo or other media item on this site, we send your name to the server. If the photo contains EXIF or IPTC data, this data may – dependant of the configuration – be saved on the server. If the photo contains GPX location data, this data will be saved on the server. If visit the site, the pages you visit, the photos you watch and your IP address will be saved on the server for statistical purposes in your session information. This information will be anonimized after one hour and removed after 24 hours. About and Credits WP Photo Album Plus is extended with many new features and is maintained by J.N. Breetvelt, ( http://www.opajaap.nl/ ) a.k.a. OpaJaap Thanx to R.J. Kaplan for WP Photo Album 1.5.1, the basis of this plugin. Licence WP Photo Album is released under the GNU GPL licence. ( http://www.gnu.org/copyleft/gpl.html )

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C