Technology · WP Photo Album Plus
WP Photo Album Plus Wp-Photo-Album-Plus vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 10 vulnerabilities in WP Photo Album Plus Wp-Photo-Album-Plus: 0 in the last 7 days and 7 in the last 90 days, 1 of them critical and 0 exploited in the wild. The most recent, CVE-2026-18579, was published on 11 September 2026.
- Last 7 days
- 0
- Last 90 days
- 7
- Critical, all time
- 1
- Exploited in the wild
- 0
About WP Photo Album Plus Wp-Photo-Album-Plus
A WordPress plugin for managing and displaying photo albums and slideshows.
Latest WP Photo Album Plus Wp-Photo-Album-Plus vulnerabilities
- CVE-2026-18579: WP Photo Album Plus stored XSS via X-Forwarded-For parameterhighCVSS 7.2EPSS 0.3%
- CVE-2026-18962: WP Photo Album Plus privilege escalation in file uploadmediumCVSS 4.3EPSS 0.3%
- CVE-2026-18049: WordPress WP Photo Album Plus unauthenticated option disclosurehighCVSS 7.5EPSS 0.4%
- CVE-2026-14922: WP Photo Album Plus stored XSS in photo-comment pipelineinfoCVSS 8
- CVE-2026-15344: WP Photo Album Plus SQL injection in export-table endpointmediumCVSS 4.9
- CVE-2026-57675: Jacob N. Breetvelt WP Photo Album Plus unauthenticated XSShighCVSS 7.1
- CVE-2026-10095: WP Photo Album Plus Stored XSS in subtext parametermediumCVSS 6.4
- CVE-2026-54829: Jacob N. Breetvelt WP Photo Album Plus SQL injectionhighCVSS 7.5
- CVE-2026-39511: WP Photo Album Plus unauthenticated SQL injectioncriticalCVSS 9.3
- CVE-2026-6379: WP Photo Album Plus SQL injection in wppa-supersearch parameterinfoCVSS 8.6
Most severe WP Photo Album Plus Wp-Photo-Album-Plus vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-39511: WP Photo Album Plus unauthenticated SQL injectioncriticalCVSS 9.3
- CVE-2026-18049: WordPress WP Photo Album Plus unauthenticated option disclosurehighCVSS 7.5EPSS 0.4%
- CVE-2026-54829: Jacob N. Breetvelt WP Photo Album Plus SQL injectionhighCVSS 7.5
- CVE-2026-18579: WP Photo Album Plus stored XSS via X-Forwarded-For parameterhighCVSS 7.2EPSS 0.3%
- CVE-2026-57675: Jacob N. Breetvelt WP Photo Album Plus unauthenticated XSShighCVSS 7.1
- CVE-2026-10095: WP Photo Album Plus Stored XSS in subtext parametermediumCVSS 6.4
- CVE-2026-15344: WP Photo Album Plus SQL injection in export-table endpointmediumCVSS 4.9
- CVE-2026-18962: WP Photo Album Plus privilege escalation in file uploadmediumCVSS 4.3EPSS 0.3%
- CVE-2026-6379: WP Photo Album Plus SQL injection in wppa-supersearch parameterinfoCVSS 8.6
- CVE-2026-14922: WP Photo Album Plus stored XSS in photo-comment pipelineinfoCVSS 8
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 2 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 2 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 2 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 1 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/photo-album-plus.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "WP Photo Album Plus Wp-Photo-Album-Plus vulnerabilities", https://junglewise.ai/threats/technologies/photo-album-plus, 26 September 2026.