CVE-2026-18048
Deferred Deferred - Pending Action

WP Photo Album Plus Arbitrary ZIP Deletion Vulnerability

Vulnerability report for CVE-2026-18048, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-12

Last updated on: 2026-08-26

Assigner: WPScan

Description

The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not validate a client-controlled value used to build a file path in one of its public endpoint actions, and performs no authorisation check on it, allowing unauthenticated attackers to delete arbitrary ZIP archives on the server, including ones stored outside the web root.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-12
Last Modified
2026-08-26
Generated
2026-09-01
AI Q&A
2026-08-12
EPSS Evaluated
2026-08-31
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
wp_photo_album_plus wp_photo_album_plus to 9.2.07.002 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-73 The product allows user input to control or influence paths or file names that are used in filesystem operations.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a path traversal issue in the WP Photo Album Plus WordPress plugin before version 9.2.07.002. It allows unauthenticated attackers to delete arbitrary ZIP archives on the server by manipulating a client-controlled value in a public endpoint. The plugin does not validate this input or perform authorization checks, enabling attackers to target files outside the web root.

Detection Guidance

Check if your WordPress site uses WP Photo Album Plus plugin version prior to 9.2.07.002. Inspect server logs for suspicious requests to the 'delmyzip' endpoint or unusual file deletion activities. No specific commands are provided in the context.

Impact Analysis

This vulnerability can lead to unauthorized file deletion on your server, including critical files outside the web root. Attackers could delete backups, configuration files, or other sensitive data, potentially causing data loss or system instability. Since it requires no authentication, any unauthenticated user can exploit it.

Compliance Impact

This vulnerability could violate compliance requirements under GDPR or HIPAA by enabling unauthorized data deletion or system compromise. GDPR requires protecting personal data integrity, while HIPAA mandates safeguarding protected health information. Unauthorized file deletion may lead to data breaches or loss of audit trails.

Mitigation Strategies

Update the WP Photo Album Plus plugin to version 9.2.07.002 or later immediately. If updating is not possible, consider disabling the plugin until the update is applied. Monitor server files for unauthorized deletions.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-18048. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart