Executive brief
WP Photo Album Plus, a popular WordPress plugin used for managing and displaying photo galleries, contains a critical security flaw. This vulnerability allows an unauthenticated attacker to interact directly with the website's database without needing a password. An exploit could lead to the theft of sensitive customer data, administrative credentials, or a partial disruption of the website's services.
Technical details
The WP Photo Album Plus plugin for WordPress is vulnerable to SQL Injection (CWE-89) in versions up to 9.1.08.001. The vulnerability stems from improper neutralization of user-supplied input before it is used in an SQL query. Because the flaw is unauthenticated, a remote attacker can exploit it over the network without any prior access or user interaction. Successful exploitation allows the attacker to read sensitive data from the database, including user records and configuration details, and potentially impact the availability of the site. The issue is resolved in version 9.1.08.002.
Affected products
- WP Photo Album Plus WP Photo Album Plus <= 9.1.08.001
Timeline
- 2026-02-17: other: Reported by researcher Martín Martín
- 2026-04-13: advisory: Patchstack advisory published
- 2026-06-15: disclosed: NVD publication date