PatchSiren

WP Photo Album Plus CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

Review WP Photo Album Plus CVE published 2026-08-09

CVE-2026-17014

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-09T06:18:17.827Z and has not been modified since then. The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not perform any capability or nonce check on one of its public REST endpoint actions, allowing unauthenticated users to delete the generated album export ZIP archives it stores. Thi [truncated]

MEDIUM WP Photo Album Plus CVE published 2026-07-31

CVE-2026-14922

The WP Photo Album Plus plugin, used for managing and displaying photo albums on WordPress sites, is vulnerable to stored Cross-Site Scripting (XSS) in all versions up to, and including, 9.2.03.001. This vulnerability exists due to a decode-after-sanitize flaw in the photo-comment pipeline, which allows an attacker to submit a double HTML-entity-encoded payload. This payload passes the write filters as ha [truncated]

HIGH WP Photo Album Plus CVE published 2026-05-18

CVE-2026-6379

WP Photo Album Plus, a WordPress plugin, contains an unauthenticated SQL injection vulnerability in versions prior to 9.1.11.001. The flaw stems from improper sanitization and escaping of a parameter used in a SQL query, allowing remote attackers to manipulate database queries without authentication. The CVSS 3.1 score of 8.6 (HIGH) reflects network attack vector, low attack complexity, no privileges requ [truncated]