What is CVE-2026-15344?
CVE-2026-15344 is an SQL Injection vulnerability in the WP Photo Album Plus plugin for WordPress via the 'table' parameter, affecting all versions up to and including 9.2.04.002. This flaw exists due to insufficient escaping of user-supplied data and lack of query preparation. Users should update the plugin to the latest patched version.
Azərbaycanca: CVE-2026-15344, WordPress WP Photo Album Plus plugininin 9.2.04.002-dək olan versiyalarında 'table' parametri vasitəsilə SQL injection zəifliyidir. Bu zəiflik istifadəçi tərəfindən daxil edilən parametrin düzgün escap edilməməsi və SQL sorğusunun hazırlanmaması səbəbindən yaranır. Pluginin ən son versiyasına yenilənməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-89
FAQ2
Which parameter is vulnerable to SQL injection in the WP Photo Album Plus plugin as per CVE-2026-15344?
The vulnerability is exploited via the 'table' parameter due to insufficient escaping of user-supplied data and lack of query preparation.
How can users protect their sites from the vulnerability described in CVE-2026-15344?
Users should update the WP Photo Album Plus plugin to the latest patched version.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.