Impact
The WP Photo Album Plus WordPress plugin versions prior to 9.2.07.002 contains a REST endpoint action named delexportzips that performs no capability or nonce verification. As a result, any user, regardless of authentication status, can invoke this action and delete the ZIP files that the plugin creates to export album data. The primary consequence is the loss of these exported archives, which constitutes an availability violation and may also result in loss of backup copies of user content.
Affected Systems
It affects the WordPress plugin WP Photo Album Plus in all releases earlier than version 9.2.07.002. Administrators using the plugin on their sites should verify that their plugin is at or above the patched version to ensure that the delexportzips action is protected or removed.
Risk and Exploitability
The vulnerability does not require privileged access and is exploitable by issuing a straightforward HTTP request to the publicly exposed REST endpoint. The EPSS score is not available; the flaw is present in the plugin, and based on the description, it is inferred that the absence of authentication checks makes the risk significant. The vulnerability is not listed in the CISA KEV catalog, but the lack of an authenticity guard for a destructive action makes it a high-severity issue in terms of potential impact.
OpenCVE Enrichment