Back

HIGH

WordPress WP Photo Album Plus plugin <= 9.1.13.005 - SQL Injection vulnerability

Published Jun 25, 2026

Description

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Jacob N. Breetvelt WP Photo Album Plus allows Blind SQL Injection.

This issue affects WP Photo Album Plus: from n/a through 9.1.13.005.

Affected products

Remediation

Vendor solution

Update the WordPress WP Photo Album Plus Plugin to the latest available version (at least 9.2.01.001).

Weaknesses (1)

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Patchstack
Published Jun 25, 2026
Updated Jun 25, 2026
Reserved Jun 16, 2026
CISA Vulnrichment
Updated Jun 25, 2026
NVD
Status Deferred
Modified Jun 25, 2026
Red Hat
Severity n/a
Public date n/a