PT-2026-71029 · WordPress · Wp Photo Album Plus
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
WP Photo Album Plus versions prior to 9.2.09.002
Description
An authorization flaw exists when processing front-end uploads, where the system fails to verify if the current user has permission to upload to the target album. This allows any authenticated user, including those with Subscriber roles, to upload files into albums owned by other users or the administrator. This issue is only exploitable if the front-end user upload feature is enabled.
Recommendations
Update to version 9.2.09.002 or later.
Disable the front-end user upload feature to mitigate the risk.
Exploit
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wp Photo Album Plus