CVE-2026-17014 PUBLISHED

WP Photo Album Plus < 9.2.07.002 - Unauthenticated Export ZIP File Deletion via delexportzips

Assigner: WPScan
Reserved: 24.07.2026 Published: 09.08.2026 Updated: 09.08.2026

The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not perform any capability or nonce check on one of its public REST endpoint actions, allowing unauthenticated users to delete the generated album export ZIP archives it stores.

Product Status

Vendor Unknown
Product WP Photo Album Plus
Versions Default: unaffected
  • affected from 0 to 9.2.07.002 (excl.)

Credits

  • Vaibhav Narkhede finder
  • WPScan coordinator

References

Problem Types

  • CWE-73 External Control of File Name or Path CWE