
CVE-2026-18962 The WP Photo Album Plus WordPress plugin before 9.2.09.002 does not check that the current user is allowed to upload into the album they target when it processes a fr… https://www.cve.org/CVERecord?id=CVE-2026-18962
Post summary
The WP Photo Album Plus WordPress plugin prior to version 9.2.09.002 fails to verify upload permissions, enabling unauthorized users to upload into albums. No PoC, exploit code, or patch details are provided beyond the CVE identifier.
