WordPress WP Photo Album Plus是WordPress基金会开源的一款CMS照片管理插件。 WordPress WP Photo Album Plus 9.2.07.002之前版本存在信息泄露漏洞,该漏洞源于未对公共端点操作执行权限或nonce检查,且使用客户端提供的值构建选项名并未限制为自身选项,可能导致未经身份验证的用户读取其他自动加载选项的值。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Unknown | WP Photo Album Plus | < 9.2.07.002 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | WP Photo Album Plus | 0 ~ 9.2.07.002 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-16747 | 6.5 MEDIUM | Kirki < 6.2.1 - Unauthenticated Arbitrary Shortcode Execution via Form Email Actions |
| CVE-2026-15045 | 6.5 MEDIUM | Wallet System for WooCommerce < 2.7.10 - Customer+ Checkout Price Manipulation via Unvalid |
| CVE-2026-17008 | 5.3 MEDIUM | Quick PayPal Payments <= 5.7.50 - Unauthenticated Payment Bypass via PayPal IPN |
| CVE-2026-16990 | 5.3 MEDIUM | Payment Button for PayPal <= 1.2.3.44 - Unauthenticated Payment Price Manipulation |
| CVE-2026-16621 | 5.3 MEDIUM | Payment Gateway for PayPal on WooCommerce < 9.2.1 - Unauthenticated Payment Bypass via Pay |
| CVE-2026-15213 | 5.3 MEDIUM | Welcart e-Commerce < 2.11.33 - Unauthenticated Payment Bypass via Forged Settlement Callba |
| CVE-2026-18044 | 3.7 LOW | Estatik Real Estate Plugin < 4.3.4 - Unauthenticated Arbitrary-Recipient Mail Relay via Si |
| CVE-2026-18789 | Ezoic < 2.23.1 - Unauthenticated Database Export via Content Export REST Routes | |
| CVE-2026-17013 | WP Photo Album Plus < 9.2.07.002 - Reflected XSS via lbstart | |
| CVE-2026-19052 | ProSolution WP Client < 2.0.9 - Subscriber+ proSol_ajaxTablesync and proSol_ajaxClearlog C | |
| CVE-2026-19073 | Order Sync with Zendesk for WooCommerce < 2.2.3 - Unauthenticated Customer Order Data Disc | |
| CVE-2026-19217 | Royal Elementor Addons < 1.7.1065 - Contributor+ Stored XSS via Icon Box Widget | |
| CVE-2026-19050 | ProSolution WP Client < 2.0.9 - Subscriber+ SSRF via proSol_url_validate | |
| CVE-2026-18943 | WPC Admin Columns < 2.3.4 - Subscriber+ Arbitrary User/Post/Term Meta Disclosure | |
| CVE-2026-18057 | Events Manager < 7.4.1 - Subscriber+ Booking Consent Record Tampering via SQL Injection | |
| CVE-2026-18366 | Events Manager < 7.4.1 - Unauthenticated Privilege Escalation to Administrator | |
| CVE-2026-18230 | WP Directory Kit < 1.5.6 - Subscriber+ SQL Injection via section Parameter | |
| CVE-2026-18391 | WooCommerce Subscriptions < 9.1.0 - Unauthenticated RCE via PHP Object Injection | |
| CVE-2026-18048 | WP Photo Album Plus < 9.2.07.002 - Unauthenticated Arbitrary ZIP File Deletion via delmyzi | |
| CVE-2026-18046 | Cookie Consent < 0.0.10 - Subscriber+ MaxMind License Key Update |
Showing top 20 of 44 CVEs. View all on vendor page → →
No comments yet