PT-2026-95739 · WordPress · Wp Photo Album Plus

·

CVE-2026-87909

·

Published

2026-09-19

·

Updated

2026-09-21

CVSS v3.1

7.5

High

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WP Photo Album Plus versions prior to 9.2.09.003
Description Authenticated users with subscriber-level access and above can achieve Remote Code Execution via the wppa image magick() function. The issue stems from insufficient sanitization of the multipart upload filename before it is concatenated into an ImageMagick command string executed via exec(). While escapeshellcmd() is applied to the entire command, it fails to prevent argument injection because spaces still act as argument separators, and the filename sanitization used at the database layer is not applied to the physical temporary file path used during ImageMagick processing.
Recommendations Update to a version newer than 9.2.09.002. As a temporary mitigation, restrict access to the wppa image magick() function for users with subscriber-level permissions.

Fix

RCE

Special Elements Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-87909

Affected Products

Wp Photo Album Plus