Impact
The WP Photo Album Plus plugin contains a flaw where the multipart upload filename is concatenated into an ImageMagick command string that is executed without proper argument quoting. Because only escapeshellcmd() is applied to the entire command, spaces remain as argument separators, allowing an attacker to inject additional command fragments. An authenticated user with subscriber-level access or higher can therefore craft a malicious filename that causes arbitrary code execution on the web‑server. The weakness is a classic command injection (CWE‑74).
Affected Systems
WordPress sites that use the WP Photo Album Plus plugin version 9.2.09.002 or earlier. Any installation of this plugin with subscriber (or higher) roles enabled for file uploads is vulnerable.
Risk and Exploitability
The vulnerability has a CVSS score of 7.5, indicating a high impact. The EPSS score is not available, and the issue is not listed in the CISA KEV catalog, so no public zero‑day exploits are documented yet. Nonetheless, the attack can be performed remotely as long as the attacker can authenticate as a subscriber or higher and upload a file with a crafted filename. Successful exploitation would give the attacker full control over the server’s command line, leading to data exfiltration, site defacement, or further lateral movement.
OpenCVE Enrichment