
Just got a CVE assigned: CVE-2026-6379 Found an unauthenticated SQL injection in WP Photo Album Plus (< 9.1.11.001). CVSS 8.6 Pre-auth, no creds needed. Verified by @_WPScan_. Patch is out, update now. https://wpscan.com/vulnerability/60b88fd2-4048-4773-b319-63caaf5bd8eb
Post summary
A newly assigned CVE-2026-6379 reveals an unauthenticated SQL injection in WP Photo Album Plus versions below 9.1.11.001, scored CVSS 8.6, with a patch already released.



