Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2021-25115

The WP Photo Album Plus WordPress plugin before 8.0.10 was vulnerable to Stored Cross-Site Scripting (XSS). Error log content was handled improperly, therefore any user, even unauthenticated, could cause arbitrary javascript to be executed in the admin panel.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 36.7%
CVSS Severity
CVSS v3 Score 6.4
CVSS v2 Score 3.5
Products affected by CVE-2021-25115


Contact Us

Shodan ® - All rights reserved