PT-2026-71029 · WordPress · Wp Photo Album Plus

·

CVE-2026-18962

·

Published

2026-08-12

·

Updated

2026-08-12

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions WP Photo Album Plus versions prior to 9.2.09.002
Description An authorization flaw exists when processing front-end uploads, where the system fails to verify if the current user has permission to upload to the target album. This allows any authenticated user, including those with Subscriber roles, to upload files into albums owned by other users or the administrator. This issue is only exploitable if the front-end user upload feature is enabled.
Recommendations Update to version 9.2.09.002 or later. Disable the front-end user upload feature to mitigate the risk.

Exploit

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-18962

Affected Products

Wp Photo Album Plus