CVE-2026-96278 | opajaap WP Photo Album Plus Plugin up to 9.3.03.002 on WordPress Output Escaping wppaEntityDecode REQUEST_URI cross site scripting
A vulnerability marked as problematic has been reported in opajaap WP Photo Album Plus Plugin up to 9.3.03.002 on WordPress. Affected by this issue is the function wppaEntityDecode of the component Output Escaping. Performing a manipulation of the argument REQUEST_URI results in cross site scripting.
This vulnerability is known as CVE-2026-96278. Remote exploitation of the attack is possible. No exploit is available.VulDB Recent EntriesRead More