What is CVE-2026-17013?
This vulnerability exists in the WP Photo Album Plus WordPress plugin before version 9.2.07.002. It arises from the failure to sanitize and escape a parameter before reflecting it into an inline script block, enabling unauthenticated attackers to perform Reflected Cross-Site Scripting (XSS) attacks. If an attacker crafts a malicious link and tricks a user into opening it, they can execute arbitrary scripts in the user's browser context, potentially compromising sensitive data or session integrity.
Azərbaycanca: Bu boşluq WP Photo Album Plus WordPress plugin-inin 9.2.07.002 versiyasından əvvəlki versiyalarında aşkarlanıb. Zəiflik, bir parametrin inline script blokuna əks olunmazdan əvvəl sanitizə edilməməsi səbəbindən yaranır. Təsdiqlənməmiş hücumçular, xüsusi hazırlanmış keçid vasitəsilə Reflected Cross-Site Scripting (XSS) hücumu həyata keçirə bilər, istifadəçiləri bu keçidə daxil olmağa aldadaraq onların brauzerində zərərli skript işlətmə riski yaradır. Plugin-i ən son versiyaya yeniləmək lazımdır.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which versions of the WP Photo Album Plus plugin are affected by CVE-2026-17013?
This vulnerability affects the WP Photo Album Plus plugin versions before 9.2.07.002.
What type of attack can an attacker perform by exploiting CVE-2026-17013?
Unauthenticated attackers can perform Reflected Cross-Site Scripting (XSS) attacks via a specially crafted link.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.