PT-2026-39315 · Undefined · Undefined

Published

2026-05-08

·

Updated

2026-05-18

·

CVE-2026-6379

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions WP Photo Album Plus versions prior to 9.1.11.001
Description The plugin fails to properly sanitize and escape a parameter before its use in a SQL query. This allows unauthenticated users to execute SQL injection attacks, which involve inserting malicious SQL statements into entry fields for execution by the database.
Recommendations Update to version 9.1.11.001 or later.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2026-6379

Affected Products

Undefined