CyberRota Analysis
AI-GeneratedThe WP Photo Album Plus plugin for WordPress prior to version 9.2.07.002 is vulnerable due to a lack of capability and nonce checks on a public endpoint, enabling unauthenticated users to access sensitive autoloaded option values. This could lead to unauthorized information disclosure, potentially exposing sensitive configuration details. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate this risk.
Original NVD Description
The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not perform any capability or nonce check on one of its public endpoint actions and builds an option name from a client-supplied value without restricting it to its own options, allowing unauthenticated users to read the value of other autoloaded options whose names end in a matching suffix.