The WP Photo Album Plus WordPress plugin before 9.1.11.001 does not properly sanitize and escape a parameter before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks.
Project Subscriptions
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 18 May 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wordpress
Wordpress wordpress Wp Photo Album Plus Project Wp Photo Album Plus Project wp Photo Album Plus |
|
| Vendors & Products |
Wordpress
Wordpress wordpress Wp Photo Album Plus Project Wp Photo Album Plus Project wp Photo Album Plus |
Mon, 18 May 2026 08:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-89 |
Mon, 18 May 2026 06:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The WP Photo Album Plus WordPress plugin before 9.1.11.001 does not properly sanitize and escape a parameter before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks. | |
| Title | WP Photo Album Plus < 9.1.11.001 - Unauthenticated SQL Injection via 'wppa-supersearch' Parameter | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-05-18T06:00:08.432Z
Reserved: 2026-04-15T17:43:43.278Z
Link: CVE-2026-6379
No data.
Status : Received
Published: 2026-05-18T07:16:12.590
Modified: 2026-05-18T07:16:12.590
Link: CVE-2026-6379
No data.
OpenCVE Enrichment
Updated: 2026-05-18T10:45:04Z
Weaknesses