Impact
The WP Photo Album Plus WordPress plugin before 9.1.11.001 fails to sanitize the 'wppa-supersearch' parameter before incorporating it into a database query. This omission allows an unauthenticated user to inject arbitrary SQL statements, potentially compromising the confidentiality and integrity of the site’s database. The weakness is a classic SQL injection, classified as CWE‑89.
Affected Systems
WordPress sites running WP Photo Album Plus plugin versions earlier than 9.1.11.001 are impacted. The vulnerability exists in all editions of the plugin where the vulnerable code path is active, regardless of user role.
Risk and Exploitability
Because the vulnerability is triggered by an unauthenticated HTTP request, any visitor can attempt an exploit without prior access or credentials. While no EPSS score is available and the vulnerability is not listed in the CISA KEV catalog, the potential impact is high due to the remote nature of the injection. The attack vector is inferred to be a standard crafted URL or form submission containing the malicious payload.
OpenCVE Enrichment