AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-17014

MEDIUM · CVSS 5.3 EPSS 0.19%

Source: NVD + CISA KEV + EPSS · Published 2026-08-09 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The WP Photo Album Plus plugin for WordPress prior to version 9.2.07.002 is vulnerable due to a lack of capability and nonce checks on a public REST endpoint, enabling unauthenticated users to delete album export ZIP archives. This vulnerability poses a risk of unauthorized data manipulation, potentially disrupting users' access to their photo albums. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate the risk.

CVE
CVE-2026-17014
Severity
MEDIUM
CVSS
5.3
EPSS
0.19%
WordPress

Original NVD Description

The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not perform any capability or nonce check on one of its public REST endpoint actions, allowing unauthenticated users to delete the generated album export ZIP archives it stores.