The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not perform any capability or nonce check on one of its public endpoint actions and builds an option name from a client-supplied value without restricting it to its own options, allowing unauthenticated users to read the value of other autoloaded options whose names end in a matching suffix.
History

Thu, 13 Aug 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Wp Photo Album Plus Project
Wp Photo Album Plus Project wp Photo Album Plus
Vendors & Products Wordpress
Wordpress wordpress
Wp Photo Album Plus Project
Wp Photo Album Plus Project wp Photo Album Plus

Wed, 12 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 12 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200

Wed, 12 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Description The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not perform any capability or nonce check on one of its public endpoint actions and builds an option name from a client-supplied value without restricting it to its own options, allowing unauthenticated users to read the value of other autoloaded options whose names end in a matching suffix.
Title WP Photo Album Plus < 9.2.07.002 - Unauthenticated Option Disclosure via gettogo
References

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-12T16:06:28.661Z

Reserved: 2026-07-28T11:37:00.927Z

Link: CVE-2026-18049

cve-icon Vulnrichment

Updated: 2026-08-12T16:06:25.447Z

cve-icon NVD

Status : Received

Published: 2026-08-12T06:19:34.650

Modified: 2026-08-12T17:17:24.697

Link: CVE-2026-18049

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T10:30:04Z