Impact
The WP Photo Album Plus plugin for WordPress allows authenticated administrators to inject arbitrary SQL via the 'table' parameter due to insufficient escaping. This flaw enables read‑only access to the database and potentially further manipulations, aligning with CWE‑89.
Affected Systems
The vulnerability affects the WP Photo Album Plus plugin, versions 9.2.04.002 and earlier, installed within WordPress sites.
Risk and Exploitability
The CVSS score of 4.9 indicates moderate risk while the EPSS score of less than 1% suggests a low probability of exploitation. Only users with administrator access can exploit the flaw, and the lack of nonce on the export‑table endpoint also allows a CSRF attack that can trigger the injection when an administrator clicks a malicious link. The vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment