What is CVE-2026-18962?
The WP Photo Album Plus WordPress plugin before version 9.2.09.002 fails to verify if the current user is allowed to upload to the targeted album during front-end uploads. This allows any authenticated user, such as a Subscriber, to upload files into albums owned by other users or the admin. Updating the plugin to the latest version is recommended.
Azərbaycanca: WP Photo Album Plus WordPress plaginində (9.2.09.002 öncəsi versiyalarda) autentifikasiya yoxlaması zəifliyi mövcuddur. Bu, istənilən autentifikasiya olunmuş istifadəçiyə (məsələn, Subscriber) digər istifadəçilərin və ya adminin albomlarına fayl yükləməyə icazə verir. Plaginin ən son versiyasına yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which versions of the WP Photo Album Plus plugin are affected by CVE-2026-18962?
Versions of the WP Photo Album Plus plugin before 9.2.09.002 are affected by this vulnerability.
How can a user with a Subscriber role exploit this authentication bypass vulnerability?
The CVE-2026-18962 vulnerability allows any authenticated user, such as a Subscriber, to upload files via front-end uploads into albums owned by other users or the admin.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.