CVE-2021-25115

Plain English Summary

AI-powered analysis for quick understanding

This vulnerability allows an attacker to inject malicious JavaScript code that can run in the admin panel of the WP Photo Album Plus plugin, potentially compromising the site. It can be exploited by any user, even those who are not logged in, simply by submitting harmful content that gets logged by the plugin.

Technical Description

The WP Photo Album Plus WordPress plugin before 8.0.10 was vulnerable to Stored Cross-Site Scripting (XSS). Error log content was handled improperly, therefore any user, even unauthenticated, could cause arbitrary javascript to be executed in the admin panel.

CVSS Vector Analysis

Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredLow
User InteractionNone
Confidentiality ImpactLow
Integrity ImpactLow
Availability ImpactNone
ScopeChanged

Vector String

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N

Exploit Resources

Search for proof-of-concept code and exploit modules

Official References

Est. Bounty
$914($500-$1K)
Vendor Response
Grade FPatched in 1495 days

Quick Information

Published

Feb 14, 2022

about 4 years ago

Last Modified

Mar 20, 2026

18 days ago

Vendor

wppa

Product

wp photo album plus