CVE-2026-14922 | WP Photo Album Plus Plugin up to 9.2.03.001 on WordPress Photo-Comment Pipeline wppa-functions.php wppa_do_comment cross site scripting

SecurityVulns

A vulnerability classified as problematic has been found in WP Photo Album Plus Plugin up to 9.2.03.001 on WordPress. Impacted is the function wppa_do_comment of the file wppa-functions.php of the component Photo-Comment Pipeline. This manipulation causes cross site scripting.

This vulnerability is tracked as CVE-2026-14922. The attack is possible to be carried out remotely. No exploit exists.

It is recommended to upgrade the affected component.VulDB Recent EntriesRead More