
🚨*CVE* CVE-2026-17013 The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not sanitise and escape a parameter before reflecting it into an inline script block, which could allo… https://www.cve.org/CVERecord?id=CVE-2026-17013 ----- Traducción: CVE-2026-17013 El … http://infoflow.cloud`
Post summary
The tweet discloses CVE‑2026‑17013, describing a client‑side script injection vulnerability in the WP Photo Album Plus WordPress plugin before version 9.2.07.002, but offers no proof of exploitation, active attacks, or patches.

