CVE-2026-6379Disclosure

LOWCVSS 8.6 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The WP Photo Album Plus WordPress plugin before 9.1.11.001 does not properly sanitize and escape a parameter before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 3d ago at 1 mentions (2026-05-03); latest day: 1
  • 4 total mentions across 4 days

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-05-03: 1Mentions · 2026-05-04: 1Mentions · 2026-05-08: 1Mentions · 2026-05-31: 1Patch / Workaround · 2026-05-03: 1Technical Details · 2026-05-03: 1Technical Details · 2026-05-04: 1Technical Details · 2026-05-08: 105-0305-0405-0805-31
Signal classification2 categories
Disclosure
375.0%
General
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-05-031
Disclosure1
2026-05-041
Disclosure1
2026-05-081
Disclosure1
2026-05-311
General1
Full discourse4 posts
  • Daniel Púa@devploit
    Disclosure

    Just got a CVE assigned: CVE-2026-6379 Found an unauthenticated SQL injection in WP Photo Album Plus (< 9.1.11.001). CVSS 8.6 Pre-auth, no creds needed. Verified by @_WPScan_. Patch is out, update now. https://wpscan.com/vulnerability/60b88fd2-4048-4773-b319-63caaf5bd8eb

    Post summary

    A newly assigned CVE-2026-6379 reveals an unauthenticated SQL injection in WP Photo Album Plus versions below 9.1.11.001, scored CVSS 8.6, with a patch already released.

    0401121.5K
    3.1K followersView on X
  • ケイ | IT・セキュリティ系副業Webライター@Teeeda_worker
    General

    【脆弱性情報】 CVE-2026-6379 WP Photo Album Plusプラグイン(バージョン9.1.11.001以前)の脆弱性について https://www.cybernote.click/2026/05/30/%e3%80%90%e8%84%86%e5%bc%b1%e6%80%a7%e6%83%85%e5%a0%b1%e3%80%91-cve-2026-6379-wp-photo-album-plus%e3%83%97%e3%83%a9%e3%82%b0%e3%82%a4%e3%83%b3%ef%bc%88%e3%83%90%e3%83%bc%e3%82%b8%e3%83%a7%e3%83%b39-1/ #IT #Security #cybersecurity

    Post summary

    The post announces a vulnerability (CVE‑2026‑6379) affecting WP Photo Album Plus and provides a link to an external article, but offers no details on exploitation or mitigation.

    0000044
    209 followersView on X
  • UNDERCODE TESTING@UndercodeUpdate
    Disclosure

    🚨 Critical #CVE-2026-6379: Unauthenticated SQL Injection in WP Photo Album Plus WordPress Plugin – #Update Immediately! + Video https://undercodetesting.com/critical-cve-2026-6379-unauthenticated-sql-injection-in-wp-photo-album-plus-wordpress-plugin-update-immediately%ef%bc%81-video/ Educational Purposes!

    Post summary

    The post announces a critical unauthenticated SQL injection flaw in the WP Photo Album Plus plugin, urging users to update but providing no PoC code or patch details.

    0000051
    550 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-6379 CVE-2026-6379 — WP Photo Album Plus < 9.1.11.001 — Unauthenticated SQL Injection Parameter https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-6379

    Post summary

    CVE-2026-6379 is an unauthenticated SQL injection vulnerability in versions of WP Photo Album Plus below 9.1.11.001; basic technical details are listed, but no PoC, exploit, or patch information is provided.

    0000049
    4.0K followersView on X

Explore more