What is CVE-2026-18049?
A vulnerability in the WP Photo Album Plus plugin (before 9.2.07.002) allows unauthenticated users to read arbitrary option values due to missing capability and nonce checks on a public endpoint. The issue arises because an option name is built from client-supplied input without restriction. Users should update the plugin to the latest version.
Azərbaycanca: WP Photo Album Plus plaginində (9.2.07.002-dən əvvəl) autentifikasiya olunmamış istifadəçilərə sistem seçimlərini oxumağa imkan verən zəiflik aşkarlanıb. Bu, müəyyən bir public endpoint-də capability və nonce yoxlamasının aparılmaması səbəbindən baş verir. İstifadəçilər plaqini ən son versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-200
FAQ2
What versions of the WP Photo Album Plus plugin are affected by CVE-2026-18049?
The vulnerability affects all versions of the plugin before 9.2.07.002.
How can I protect against CVE-2026-18049?
You should update the WP Photo Album Plus plugin to the latest version.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.