AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-09T06:18:17.827Z and has not been modified since then. The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not perform any capability or nonce check on one of its public REST endpoint actions, allowing unauthenticated users to delete the generated album export ZIP archives it stores. Thi [truncated]
The WP Photo Album Plus plugin, used for managing and displaying photo albums on WordPress sites, is vulnerable to stored Cross-Site Scripting (XSS) in all versions up to, and including, 9.2.03.001. This vulnerability exists due to a decode-after-sanitize flaw in the photo-comment pipeline, which allows an attacker to submit a double HTML-entity-encoded payload. This payload passes the write filters as ha [truncated]
WP Photo Album Plus, a WordPress plugin, contains an unauthenticated SQL injection vulnerability in versions prior to 9.1.11.001. The flaw stems from improper sanitization and escaping of a parameter used in a SQL query, allowing remote attackers to manipulate database queries without authentication. The CVSS 3.1 score of 8.6 (HIGH) reflects network attack vector, low attack complexity, no privileges requ [truncated]