AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-18049

HIGH · CVSS 7.5 EPSS 0.28%

Source: NVD + CISA KEV + EPSS · Published 2026-08-12 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

The WP Photo Album Plus plugin for WordPress prior to version 9.2.07.002 is vulnerable due to a lack of capability and nonce checks on a public endpoint, enabling unauthenticated users to access sensitive autoloaded option values. This could lead to unauthorized information disclosure, potentially exposing sensitive configuration details. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate this risk.

CVE
CVE-2026-18049
Severity
HIGH
CVSS
7.5
EPSS
0.28%
WordPress

Original NVD Description

The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not perform any capability or nonce check on one of its public endpoint actions and builds an option name from a client-supplied value without restricting it to its own options, allowing unauthenticated users to read the value of other autoloaded options whose names end in a matching suffix.