
🚨*CVE* CVE-2026-18048 The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not validate a client-controlled value used to build a file path in one of its public endpoint actions… https://www.cve.org/CVERecord?id=CVE-2026-18048 ----- Traducción: CVE-2026-18048 El … http://infoflow.cloud`
Post summary
The note announces CVE‑2026‑18048 in the WP Photo Album Plus plugin, highlighting that it fails to validate a client‑controlled file‑path value used in a public endpoint action.

