
🚨*CVE* CVE-2026-18049 The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not perform any capability or nonce check on one of its public endpoint actions and builds an option n… https://www.cve.org/CVERecord?id=CVE-2026-18049 ----- Traducción: CVE-2026-18049 El … http://infoflow.cloud`
Post summary
The tweet announces CVE‑2026‑18049, notes a missing capability/nonce check in WP Photo Album Plus v9.2.07.002‑below, and links to the CVE record, but provides no PoC, exploit code, patch, or evidence of active exploitation.

