Beveiligingsadvies

CVE-2026-17013

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-08-12 06:00:16
Laatst bijgewerkt 2026-08-12 16:07:21
Toegewezen door WPScan
CVSS-score 6.1
Status PUBLISHED

Beschrijving

The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not sanitise and escape a parameter before reflecting it into an inline script block, which could allow unauthenticated attackers to perform Reflected Cross-Site Scripting attacks against anyone who is tricked into opening a crafted link to a page displaying one of its galleries.