CyberRota Analysis
AI-GeneratedThe WP Photo Album Plus plugin for WordPress prior to version 9.2.07.002 is vulnerable due to a lack of capability and nonce checks on a public REST endpoint, enabling unauthenticated users to delete album export ZIP archives. This vulnerability poses a risk of unauthorized data manipulation, potentially disrupting users' access to their photo albums. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate the risk.
Original NVD Description
The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not perform any capability or nonce check on one of its public REST endpoint actions, allowing unauthenticated users to delete the generated album export ZIP archives it stores.