CVE-2026-18049
Deferred Deferred - Pending Action

Unauthenticated Option Value Read in WP Photo Album Plus

Vulnerability report for CVE-2026-18049, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-12

Last updated on: 2026-08-26

Assigner: WPScan

Description

The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not perform any capability or nonce check on one of its public endpoint actions and builds an option name from a client-supplied value without restricting it to its own options, allowing unauthenticated users to read the value of other autoloaded options whose names end in a matching suffix.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-12
Last Modified
2026-08-26
Generated
2026-09-01
AI Q&A
2026-08-12
EPSS Evaluated
2026-08-31
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
wp_photo_album_plus wp_photo_album_plus to 9.2.07.002 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-200 The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the WP Photo Album Plus WordPress plugin before version 9.2.07.002. It allows unauthenticated users to read sensitive autoloaded options by exploiting a public endpoint that lacks capability or nonce checks. The plugin builds an option name from user input without restricting it to its own options, enabling access to other options with matching suffixes.

Detection Guidance

Check the installed version of the WP Photo Album Plus plugin. If it is below 9.2.07.002, the system is vulnerable. Use WordPress admin panel or run a command like 'wp plugin list' in the WordPress directory to verify the version.

Impact Analysis

Unauthenticated attackers could access sensitive data stored in WordPress options, such as API keys, passwords, or configuration details. This could lead to further attacks, data breaches, or unauthorized access to the site.

Compliance Impact

This vulnerability could result in unauthorized access to personal or sensitive data, violating GDPR and HIPAA compliance. Organizations may face legal penalties, reputational damage, and loss of trust due to data exposure.

Mitigation Strategies

Update the WP Photo Album Plus plugin to version 9.2.07.002 or later immediately. Remove or disable the plugin if an update is not available. Regularly monitor for plugin updates and security advisories.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-18049. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart