The WP Photo Album Plus plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 8.7.02.003. This is due to the plugin allowing unauthenticated users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.
Metrics
Affected Vendors & Products
References
History
Fri, 04 Apr 2025 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Wppa
Wppa wp Photo Album Plus |
|
Weaknesses | CWE-94 | |
CPEs | cpe:2.3:a:wppa:wp_photo_album_plus:*:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Wppa
Wppa wp Photo Album Plus |

Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2024-08-01T20:26:57.318Z
Reserved: 2024-04-22T18:28:05.517Z
Link: CVE-2024-4037

Updated: 2024-08-01T20:26:57.318Z

Status : Analyzed
Published: 2024-05-24T09:15:08.873
Modified: 2025-04-04T17:52:02.887
Link: CVE-2024-4037

No data.