WP Photo Album Plus
by Jacob N. Breetvelt · Media
Also makes 3 other plugins · 10.3K+ installs across the portfolio →
This plugin is more than just a photo album plugin, it is a complete, highly customizable multimedia cms and display system.
88 health vs 59 average across 2,206 Media plugins
Directory ranking optimization
How it's scored →How well this listing is tuned to rank in WordPress.org search, on the factors an owner controls. Not popularity, optimization.
Excellent listing optimization
Biggest win: Support resolution
To rank higher: Mark more forum threads resolved — the resolved ratio feeds the ranking.
Get the full rank-higher report →Daily downloads
Since 2022-10-05 · 1,424 days · wp.org + Plugin Pulse archive
30-day downloads
Rolling 30-day volume · peaks are release surges
19.1K
now · peak 27.2K
Directory rank vs rivals
wp.org popularity rank over time · higher is better · when a rival's line climbs above yours, they've overtaken you
Rating trend
Star average over time · dips mark rough releases
Update activity
How busy the existing users are, measured as downloads in the last 30 days for every 1,000 active sites. A spike means a new release everyone's pulling; a long, slow decline means an aging user base that updates less.
Release cadence
Actively maintainedHow often this plugin actually ships. A steady rhythm is the maintenance signal a single "last updated" date can't show.
38
releases in the last 12 months
2mo ago
latest release · v9.2.05.001
61
tagged releases on record
Recent releases
What its installed base runs
via wordpress.orgShare of active installs on each version of this plugin · 31% run the current release. Green is the current release; a big slice on older versions is a user base that has stopped updating.
Estimated active installs
The public count shows “10K+”. Our estimate pins where the real number sits.
Modeled within the band wp.org reports; tightens as we track daily.
Install history · since 2015-03-10 · 1,488 observations
Estimated value
What this plugin might earn a year, and what it might sell for. Modeled from public signals; we don't see anyone's books.
Est. annual revenue
Est. acquisition value
No paid tier is visible, so we don't put a figure on revenue or sale value: that would be guessing. The install base is a real asset to an acquirer, just not one public data lets us price.
Details
- Version
- 9.2.10.004
- Last updated
- 15d ago
- Added
- 2010-02-03 · 16 yrs old
- Requires WP
- 6.9
- Tested up to
- 7.1
- Requires PHP
- 5.5
Recent reviews
All reviews on wp.org ↗- ★★★★★ bodzio161.5y ago
To be honest, after using it for few years you have to say it is way over expectations! Any! And a full commitment of the author to look for our needs, update it for free is something you just cannot admire enough.
Read on wp.org ↗ - ★★★★★ neil402.6y ago
Our website has used this plugin for our Photography galleries for some time now. It is the best one out there in my opinion. The author Jacob is very pro-active and extremely helpful, resolving issues very quickly. Highly recommended plugin.
Read on wp.org ↗ - ★★★★★ Oleksandra3.3y ago
Plugin is great and really powerful with lots of settings. But it ”eats” a lot of memory so other plugins stopped working. I do not need all those numerous settings, I just need a gallery with possibility for users to download and comment pictures from frontend, so I decided to look for another decision. I`ve made contribution in translating this plugin into Ukrainian. Wish you luck 🙂
Read on wp.org ↗ - ★★★★★ qnkov4.7y ago
The plugin is amazing. It has a lot of options.
Read on wp.org ↗ - ★★★★★ mwschaff4.9y ago
I wanted to display my photo on my website by allowing users to select an album with photos grouped by category (B&W, Landscape, People, etc.) from which they would see a gallery of thumbnails of all the images. By clicking on the thumbnail they could see a larger version of the image. Finally, if they are interested in buying the image they can click on the large version which takes them to my third-party order fulfillment site. WP Photo Album Plus was the only plugin the could provide this type of functionality that I could find. It works great. The developer, Jacob N. Breetvelt, is very responsive and helpful also if there is ever an issue or question. I highly recommend this plugin.
Read on wp.org ↗ - ★★★★★ sbuwp5.5y ago
I use WP Photo Album Plus for the presentation of historical postcards. It is a fantastically powerful tool with a lot of possibilities. Especially the mass import of images with the corresponding data as CSV file were crucial for me. But the other functions are also impressive with very many setting options. Furthermore, the very fast support for questions of understanding or also function extensions is extremely good. Many thanks to Jakob and the other supporters.
Read on wp.org ↗ - ★★★★★ mlecat5.5y ago
Already 6000 albums and nearly 50000 photos in my website and it works perfectly, and “cherry on the cake” the support is very responsive and open to changes. Great plugin, great developer. This topic was modified 5 years, 4 months ago by mlecat.
Read on wp.org ↗ - ★★★★★ Anonymous User 159329325.5y ago
🙂 super plugin
Read on wp.org ↗
Known vulnerabilities
via Wordfence Intelligence30 disclosed vulnerabilities on record for this plugin, all fixed in the current version. Sites on older versions stay exposed until they update.
- Medium · 6.4 WP Photo Album Plus < 9.2.04.003 - Authenticated (Subscriber+) Stored Cross-Site Scripting ↗2026-08-13 CVE-2026-14922 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 9.2.04.003 Patched in 9.2.04.003
- 2026-08-10 CVE-2026-17013 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 9.2.07.1 Patched in 9.2.07.002
- 2026-08-10 CVE-2026-18962 Authorization Bypass Through User-Controlled Key Affects <= 9.2.09.1 Patched in 9.2.09.002
- Critical · 9.1 Photo Album Plus <= 9.2.07.1 - Arbitrary File Deletion to Unauthenticated Arbitrary ZIP File Deletion ↗2026-08-10 CVE-2026-18048 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Affects <= 9.2.07.1 Patched in 9.2.07.002
- 2026-08-03 CVE-2026-17014 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Affects <= 9.2.07.1 Patched in 9.2.07.002
- Medium · 4.9 WP Photo Album Plus <= 9.2.04.002 - Authenticated (Administrator+) SQL Injection via 'table' Parameter ↗2026-07-28 CVE-2026-15344 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 9.2.04.002 Patched in 9.2.04.003
- 2026-06-30 CVE-2026-10095 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 9.1.13.005 Patched in 9.2.01.001
- 2026-06-30 CVE-2026-57675 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 9.2.02.004 Patched in 9.2.03.001
- 2026-06-17 CVE-2026-54829 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 9.1.13.005 Patched in 9.2.01.001
- 2026-06-11 CVE-2026-6379 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects < 9.1.11.001 Patched in 9.1.11.001
- 2026-04-13 CVE-2026-39511 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 9.1.08.001 Patched in 9.1.08.002
- 2026-01-06 CVE-2025-14835 Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) Affects <= 9.1.05.008 Patched in 9.1.05.009
- Medium · 5.4 WP Photo Album Plus <= 9.0.11.006 - Authenticated (Subscriber+) Stored Cross-Site Scripting via wppa_user_upload ↗2025-10-03 CVE-2025-8726 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 9.0.11.006 Patched in 9.0.11.007
- 2024-11-10 CVE-2024-10958 Improper Control of Generation of Code ('Code Injection') Affects <= 8.8.08.007 Patched in 8.9.01.001
- 2024-10-16 CVE-2024-9951 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 8.8.05.003 Patched in 8.8.07.004
- Medium · 6.4 WP Photo Album Plus <= 8.8.02.002 - Authenticated (Subscriber+) Stored Cross-Site Scripting ↗2024-07-11 CVE-2024-38713 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 8.8.02.002 Patched in 8.8.02.003
- 2024-06-28 CVE-2024-37416 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 8.8.00.002 Patched in 8.8.00.003
- 2024-05-23 CVE-2024-4037 Improper Control of Generation of Code ('Code Injection') Affects <= 8.7.00.003 Patched in 8.7.00.004
- 2024-05-07 CVE-2024-31377 Unrestricted Upload of File with Dangerous Type Affects <= 8.7.01.001 Patched in 8.7.01.002
- Critical · 9.9 WP Photo Album Plus <= 8.6.03.004 - Authenticated (Subscriber+) Arbitrary File Upload ↗2024-04-05 CVE-2024-31286 Unrestricted Upload of File with Dangerous Type Affects <= 8.6.03.004 Patched in 8.6.03.005
- Medium · 5.3 WP Photo Album Plus <= 8.5.02.005 - IP Spoofing ↗
- 2023-12-05 CVE-2023-49813 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 8.5.02.005 Patched in 8.6.01.005
- 2023-12-05 CVE-2023-49812 Authorization Bypass Through User-Controlled Key Affects <= 8.5.02.005 Patched in 8.6.01.005
- 2022-01-02 CVE-2021-25115 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 8.0.10 Patched in 8.1.00
- 2015-05-20 CVE-2015-3647 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 6.1.3 Patched in 6.1.3
- 2014-11-06 CVE-2014-8814 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 5.4.17 Patched in 5.4.18
- 2014-09-17 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 5.4.7 Patched in 5.4.8
- Medium · 6.1 WP Photo Album Plus < 5.0.3 - Cross-Site Scripting ↗2013-05-06 CVE-2013-3254 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 5.0.3 Patched in 5.0.3
- Critical · 9.8 WP Photo Album Plus <= 1.1 - SQL Injection ↗2008-02-25 CVE-2008-0939 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 1.0 Patched in 1.1
Vulnerability records provided by Wordfence Intelligence. Copyright 2012-2026 Defiant Inc. License and terms.
CVE records: Copyright 1999-2026 The MITRE Corporation. CVE terms of use.
Behavioral tests
via WP HiveAutomated install-time checks, tested on PHP 8.1.12 · WP 7.0.1
Languages
via translate.wordpress.orgTranslated into 50 languages, 8 at 90% or more
Plus 26 more locales with partial translations.
Growth timeline
Install-tier crossings we have observed, and how long each tier took to outgrow
No tier crossings observed yet.
Competes with
The plugins that solve the same job, ranked by shared tags then reach, closest match first. The letter on the right is each plugin's health grade (A best, F worst).
-
Firelight Lightbox 200K+ installs · 4.8★ · 2 shared tags A -
Presto Player 100K+ installs · 4.8★ · 2 shared tags A -
LightPress Lightbox 40K+ installs · 4.5★ · 2 shared tags A -
Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … 20K+ installs · 4.2★ · 2 shared tags A -
WP Colorbox 5K+ installs · 4.2★ · 2 shared tags B -
Embedly 2K+ installs · 3.6★ · 2 shared tags B
Embed this report card
Drop a live Pulse card for WP Photo Album Plus into a readme, a review or a deck. It updates itself.
<iframe src="https://plugins.wpmayor.com/embed/wp-photo-album-plus" width="480" height="300" style="border:0" loading="lazy" title="WP Photo Album Plus — Plugin Pulse"></iframe> WP Photo Album Plus: 10K+ active installs, 4.7★ (199 reviews). Plugin Pulse (WP Mayor), as of 2026-08-29. https://plugins.wpmayor.com/plugin/wp-photo-album-plus