Junglewise Threat Intelligence

CVE-2026-54829: Jacob N. Breetvelt WP Photo Album Plus SQL injection

CVE-2026-54829 · Severity: high · CVSS 7.5 · Published 2026-06-25

Technologies: Jacob N. Breetvelt WP Photo Album Plus.

Executive brief

A vulnerability exists in the WP Photo Album Plus plugin for WordPress, which is used to manage and display photo galleries. An attacker could exploit this flaw to gain unauthorized access to the website's database, potentially stealing sensitive information or customer data. This issue can be triggered remotely without needing a username or password.

Technical details

The WP Photo Album Plus plugin for WordPress contains a blind SQL injection vulnerability due to improper neutralization of special elements in SQL commands. The flaw allows an unauthenticated remote attacker to execute arbitrary SQL queries against the backend database. While the attack complexity is rated as high, a successful exploit could lead to full data exfiltration (Confidentiality: High) and minor service disruption (Availability: Low). The vulnerability is fixed in version 9.2.01.001.

Affected products

  • Jacob N. Breetvelt WP Photo Album Plus up to 9.1.13.005

Timeline

  • 2026-05-07: other: Reported by researcher daroo
  • 2026-06-17: advisory: Patchstack advisory published
  • 2026-06-25: disclosed: CVE published to NVD
  • 2026-06-25: patched: Patch available in version 9.2.01.001

References