Impact
WP Photo Album Plus prior to 9.2.07.002 fails to validate a client‑controlled value used to build a file path and performs no authorisation check, allowing an unauthenticated attacker to delete arbitrary ZIP archives, including those outside the web root. The vulnerability can lead to loss of stored media, site functionality disruption, and potential exposure of sensitive content if ZIP files contain confidential data. The weakness corresponds to path traversal and missing authorisation checks, which are classic sources of data loss and integrity compromise.
Affected Systems
WordPress installations running WP Photo Album Plus versions earlier than 9.2.07.002 are affected. The plugin is commonly deployed as a public WordPress plugin and can be present on sites without special vetting. If the plugin is disabled or removed a potential attack surface is eliminated.
Risk and Exploitability
The vulnerability does not require authentication, so any visitor with access to the public endpoint can launch the deletion payload. While the CVSS score is not published, the lack of an EPSS score and absence from the KEV catalogue imply that it is not yet a known, widely exploited issue, yet the simplicity of exploitation and the absence of mitigations suggest a high risk if the plugin remains vulnerable. Attackers can trigger file deletion by providing a crafted path parameter to the vulnerable endpoint, bypassing any checks on the server side.
OpenCVE Enrichment