Impact
WP Photo Album Plus versions older than 9.2.07.002 accept a user supplied value to form a file path in a public endpoint without validating or authorizing it. Because the plugin does not restrict the value, an unauthenticated user can supply a crafted path that points to any ZIP archive stored on the server, including files located outside the web root. This vulnerability allows the attacker to delete those archives entirely, resulting in loss of stored media and potentially disrupting site functionality.
Affected Systems
WordPress sites that have the plugin installed with a version prior to 9.2.07.002 are vulnerable. The plugin is distributed through the official WordPress plugin repository, so any site that uses this plugin without keeping it up‑to‑date is at risk. The vulnerability applies to the public deletion endpoint named delmyzip, which is accessible to all visitors.
Risk and Exploitability
The flaw can be exploited without authentication by sending a crafted request to the delmyzip endpoint. The CVSS score of 7.5 reflects a moderate to high impact and the lack of requirement for authentication. The EPSS score of less than 1% suggests that, while the severity is notable, exploitation activity is currently rare. The vulnerability is not listed in the CISA KEV catalog, indicating no widespread active exploitation. Because the attack only requires a crafted HTTP request, the attack surface is broad and the risk to affected sites is significant.
OpenCVE Enrichment