What is CVE-2026-17014?
The WP Photo Album Plus plugin before version 9.2.07.002 lacks capability and nonce checks on a public REST endpoint, allowing unauthenticated users to delete generated album export ZIP archives. Immediate update to the latest version is required to mitigate this vulnerability.
Azərbaycanca: WP Photo Album Plus plugininin 9.2.07.002-dən əvvəlki versiyalarında bir REST endpointində heç bir icazə (capability) və ya nonce yoxlaması aparılmır. Bu zəiflik autentifikasiya olunmamış istifadəçilərə yaradılmış albom ixrac ZIP arxivlərini silməyə imkan verir. Plugin dərhal ən son versiyaya yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which versions of the WP Photo Album Plus plugin are affected by CVE-2026-17014?
This vulnerability affects versions of the WP Photo Album Plus plugin before 9.2.07.002.
What does CVE-2026-17014 allow an unauthenticated user to do?
It allows unauthenticated users to delete generated album export ZIP archives.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.