CVE-2026-17014
Received Received - Intake

Unauthenticated Album Export Deletion in WP Photo Album Plus

Vulnerability report for CVE-2026-17014, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-09

Last updated on: 2026-08-09

Assigner: WPScan

Description

The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not perform any capability or nonce check on one of its public REST endpoint actions, allowing unauthenticated users to delete the generated album export ZIP archives it stores.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-09
Last Modified
2026-08-09
Generated
2026-08-09
AI Q&A
2026-08-09
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
wp_photo_album_plus wp_photo_album_plus to 9.2.07.002 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the WP Photo Album Plus WordPress plugin before version 9.2.07.002. It involves a public REST endpoint action that lacks proper capability or nonce checks, allowing unauthenticated users to delete export ZIP archives created by the plugin.

Detection Guidance

Check if your WordPress site uses WP Photo Album Plus plugin version prior to 9.2.07.002. Inspect server logs for unusual REST endpoint access attempts or deletions of ZIP archives.

Impact Analysis

Unauthenticated attackers could delete important export ZIP archives generated by the plugin, potentially causing data loss or disrupting functionality for users relying on those exports.

Compliance Impact

This vulnerability could potentially impact compliance with GDPR and HIPAA by allowing unauthorized deletion of data. Under GDPR, unauthorized deletion of personal data may violate integrity and availability principles. For HIPAA, improper handling of protected health information through unauthorized deletion could breach security requirements.

Mitigation Strategies

Update the WP Photo Album Plus plugin to version 9.2.07.002 or later immediately. If updating is not possible, consider disabling the plugin until an update is applied.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-17014. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart