What is CVE-2026-18048?
The WP Photo Album Plus WordPress plugin (versions before 9.2.07.002) fails to validate a client-controlled value used in file path construction and lacks authorization checks on a public endpoint. This allows unauthenticated attackers to delete arbitrary ZIP archives on the server. Immediate update to the latest patched version is recommended.
Azərbaycanca: WP Photo Album Plus WordPress plaginində (9.2.07.002-dən əvvəlki versiyalarda) autentifikasiya və fayl yolu təsdiqi çatışmazlığı aşkarlanıb. Bu boşluq autentifikasiya olunmamış hücumçulara serverdəki ixtiyari ZIP arxivlərini silməyə imkan verir. Plagindən istifadə edən saytlar dərhal ən son versiyaya yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-22
FAQ2
Who can exploit the CVE-2026-18048 vulnerability in WP Photo Album Plus?
Unauthenticated attackers can exploit this vulnerability.
What type of files are affected by CVE-2026-18048?
The vulnerability allows deletion of arbitrary ZIP archives on the server.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.