Junglewise Threat Intelligence

CVE-2026-39511: WP Photo Album Plus unauthenticated SQL injection

CVE-2026-39511 · Severity: critical · CVSS 9.3 · Published 2026-06-15

Executive brief

WP Photo Album Plus, a popular WordPress plugin used for managing and displaying photo galleries, contains a critical security flaw. This vulnerability allows an unauthenticated attacker to interact directly with the website's database without needing a password. An exploit could lead to the theft of sensitive customer data, administrative credentials, or a partial disruption of the website's services.

Technical details

The WP Photo Album Plus plugin for WordPress is vulnerable to SQL Injection (CWE-89) in versions up to 9.1.08.001. The vulnerability stems from improper neutralization of user-supplied input before it is used in an SQL query. Because the flaw is unauthenticated, a remote attacker can exploit it over the network without any prior access or user interaction. Successful exploitation allows the attacker to read sensitive data from the database, including user records and configuration details, and potentially impact the availability of the site. The issue is resolved in version 9.1.08.002.

Affected products

  • WP Photo Album Plus WP Photo Album Plus <= 9.1.08.001

Timeline

  • 2026-02-17: other: Reported by researcher Martín Martín
  • 2026-04-13: advisory: Patchstack advisory published
  • 2026-06-15: disclosed: NVD publication date

References

Related threats