WP Photo Album Plus <= 9.1.08.001 - Unauthenticated SQL Injection
WP Photo Album Plus
Minimum safe version
9.1.08.002
Update to 9.1.08.002 or later to address 31 fixable vulnerabilities
CVE-2025-14835
WordPress WP Photo Album Plus Plugin <= 9.0.11.006 is vulnerable to Cross Site Scripting (XSS)
WordPress WP Photo Album Plus Plugin <= 8.8.08.007 is vulnerable to Broken Access Control
CVE-2024-9951
CVE-2024-38713
CVE-2024-37416
CVE-2024-4037
CVE-2024-31377
CVE-2024-31286
CVE-2023-49774
CVE-2023-49812
CVE-2023-49813
WP Photo Album Plus <= 4.1.1 - SQL Injection
WP Photo Album Plus < 4.8.12 - wp-photo-album-plus.php wppa-searchstring XSS
WP Photo Album Plus - wp-admin/admin.php edit_id Parameter XSS
WP Photo Album Plus - index.php wppa-tag Parameter XSS
WP Photo Album Plus - Full Path Disclosure
WP Photo Album Plus 5.4.5 - 5.4.8 Stored XSS
WP Photo Album Plus 5.4.4 & 5.4.3 Cross-Site Scripting (XSS)
WP Photo Album Plus <= 5.4.7 - Stored Cross-Site Scripting
WordPress Photo Album Plus Plugin <= 4.1.1 - SQL Injection
WordPress WP Photo Album Plus Plugin <= 4.8.11 - XSS
WordPress WP Photo Album Plus Plugin <= 5.4.17 Reflected XSS
WordPress WP Photo Album Plus Plugin <= 5.4.8 - Stored XSS
WordPress WP Photo Album Plus Plugin <= 5.0.10 - XSS
WordPress WP Photo Album Plus Plugin <= 4.9.2 - XSS
WordPress WP Photo Album Plus Plugin <= 4.9.0 - Full Path Disclosure
WordPress WP Photo Album Plus Plugin <= 5.4.4 - Cross Site Scripting
CVE-2013-3254
CVE-2015-3647
CVE-2021-25115