Executive brief
WP Photo Album Plus, a popular WordPress plugin used for managing and displaying photo galleries, contains a security flaw that allows unauthorized individuals to interfere with the website's database. By exploiting this vulnerability, an attacker could potentially steal sensitive user information, modify site content, or gain administrative access. Website owners should update to version 9.1.11.001 or later immediately to protect their data and operations.
Technical details
A SQL injection vulnerability exists in the WP Photo Album Plus plugin for WordPress due to insufficient sanitization and escaping of the 'wppa-supersearch' parameter. This flaw allows an unauthenticated remote attacker to append malicious SQL commands to legitimate queries. Successful exploitation could lead to full database compromise, including the extraction of sensitive data such as user credentials or the modification of database records. The issue is fixed in version 9.1.11.001.
Affected products
- WP Photo Album Plus WP Photo Album Plus < 9.1.11.001
Timeline
- 2026-04-27: disclosed: Initial public disclosure by WPScan
- 2026-04-27: patched: Fix released in version 9.1.11.001
- 2026-05-18: advisory: NVD publication date