PT-2026-69268 · WordPress · Wp Photo Album Plus
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
WP Photo Album Plus versions prior to 9.2.07.002
Description
The plugin fails to perform capability or nonce checks on a public REST endpoint action. This allows unauthenticated users to delete generated album export ZIP archives stored by the system via the
delexportzips action. A nonce is a unique token used to prevent replay attacks by ensuring that a request is intentional and comes from a trusted source.Recommendations
Update to version 9.2.07.002 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wp Photo Album Plus