Description
The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not perform any capability or nonce check on one of its public REST endpoint actions, allowing unauthenticated users to delete the generated album export ZIP archives it stores.
Published: 2026-08-09
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The WP Photo Album Plus WordPress plugin versions prior to 9.2.07.002 contains a REST endpoint action named delexportzips that performs no capability or nonce verification. As a result, any user, regardless of authentication status, can invoke this action and delete the ZIP files that the plugin creates to export album data. The primary consequence is the loss of these exported archives, which constitutes an availability violation and may also result in loss of backup copies of user content.

Affected Systems

It affects the WordPress plugin WP Photo Album Plus in all releases earlier than version 9.2.07.002. Administrators using the plugin on their sites should verify that their plugin is at or above the patched version to ensure that the delexportzips action is protected or removed.

Risk and Exploitability

The vulnerability does not require privileged access and is exploitable by issuing a straightforward HTTP request to the publicly exposed REST endpoint. The EPSS score is not available; the flaw is present in the plugin, and based on the description, it is inferred that the absence of authentication checks makes the risk significant. The vulnerability is not listed in the CISA KEV catalog, but the lack of an authenticity guard for a destructive action makes it a high-severity issue in terms of potential impact.

Generated by OpenCVE AI on August 9, 2026 at 08:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade WP Photo Album Plus to version 9.2.07.002 or later to ensure the delexportzips endpoint requires proper authentication.
  • Configure your web server or firewall to block unauthenticated requests to the /wp-json/wp-photo-album-plus/v1/delexportzips REST endpoint if an immediate upgrade is not possible.
  • If the export feature is not needed, disable or remove the export functionality in the plugin settings to eliminate the vulnerable endpoint.

Generated by OpenCVE AI on August 9, 2026 at 08:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 09 Aug 2026 08:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Sun, 09 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Description The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not perform any capability or nonce check on one of its public REST endpoint actions, allowing unauthenticated users to delete the generated album export ZIP archives it stores.
Title WP Photo Album Plus < 9.2.07.002 - Unauthenticated Export ZIP File Deletion via delexportzips
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-09T06:00:12.516Z

Reserved: 2026-07-24T10:12:26.964Z

Link: CVE-2026-17014

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-09T08:30:17Z

Weaknesses