PT-2026-69268 · WordPress · Wp Photo Album Plus

·

CVE-2026-17014

·

Published

2026-08-09

·

Updated

2026-08-11

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions WP Photo Album Plus versions prior to 9.2.07.002
Description The plugin fails to perform capability or nonce checks on a public REST endpoint action. This allows unauthenticated users to delete generated album export ZIP archives stored by the system via the delexportzips action. A nonce is a unique token used to prevent replay attacks by ensuring that a request is intentional and comes from a trusted source.
Recommendations Update to version 9.2.07.002 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-17014

Affected Products

Wp Photo Album Plus