CVE-2026-18962
Deferred Deferred - Pending Action

Unauthorized File Upload in WP Photo Album Plus

Vulnerability report for CVE-2026-18962, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-12

Last updated on: 2026-08-26

Assigner: WPScan

Description

The WP Photo Album Plus WordPress plugin before 9.2.09.002 does not check that the current user is allowed to upload into the album they target when it processes a front-end upload, allowing any authenticated user, such as a Subscriber, to upload files into albums owned by other users or by the administrator. Exploitation requires the WP Photo Album Plus WordPress plugin before 9.2.09.002's front-end user upload feature to be enabled, which is not the default.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-12
Last Modified
2026-08-26
Generated
2026-09-01
AI Q&A
2026-08-12
EPSS Evaluated
2026-08-31
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
wp_photo_album_plus wp_photo_album_plus to 9.2.09.002 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an Insecure Direct Object Reference (IDOR) in the WP Photo Album Plus WordPress plugin before version 9.2.09.002. It allows any authenticated user, including low-privilege users like Subscribers, to upload files into albums owned by other users or administrators. The issue occurs because the plugin fails to verify if the user has permission to upload to the target album.

Detection Guidance

Check if the WP Photo Album Plus plugin is installed and verify its version. If it is below 9.2.09.002 and the front-end upload feature is enabled, the system is vulnerable. Look for unauthorized file uploads in user or admin albums.

Impact Analysis

If you use the WP Photo Album Plus plugin with the front-end upload feature enabled, attackers could upload malicious files to your albums. This could lead to unauthorized content being added to your site, potential malware distribution, or defacement of your photo albums.

Compliance Impact

This vulnerability could impact compliance by allowing unauthorized file uploads, potentially violating data integrity and access control requirements in GDPR and HIPAA. Unauthorized uploads may expose sensitive data or introduce malicious content, leading to regulatory penalties.

Mitigation Strategies

Update the WP Photo Album Plus plugin to version 9.2.09.002 or later immediately. If updating is not possible, disable the front-end user upload feature to prevent exploitation.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-18962. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart