Description
The WP Photo Album Plus plugin for WordPress is vulnerable to Remote Code Execution in all versions via the wppa_image_magick function. This is due to insufficient sanitization of the multipart upload filename before concatenation into an ImageMagick command string executed via exec(), with only escapeshellcmd() applied to the whole command rather than quoting individual arguments. This makes it possible for authenticated attackers, with subscriber-level access and above, to execute code on the server. escapeshellcmd() escapes shell metacharacters but does not prevent argument injection because spaces remain as argument separators, and the filename sanitization applied at the database layer is never applied to the physical temporary file path used for ImageMagick processing.
Published: 2026-09-19
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The WP Photo Album Plus plugin contains a flaw where the multipart upload filename is concatenated into an ImageMagick command string that is executed without proper argument quoting. Because only escapeshellcmd() is applied to the entire command, spaces remain as argument separators, allowing an attacker to inject additional command fragments. An authenticated user with subscriber-level access or higher can therefore craft a malicious filename that causes arbitrary code execution on the web‑server. The weakness is a classic command injection (CWE‑74).

Affected Systems

WordPress sites that use the WP Photo Album Plus plugin version 9.2.09.002 or earlier. Any installation of this plugin with subscriber (or higher) roles enabled for file uploads is vulnerable.

Risk and Exploitability

The vulnerability has a CVSS score of 7.5, indicating a high impact. The EPSS score is not available, and the issue is not listed in the CISA KEV catalog, so no public zero‑day exploits are documented yet. Nonetheless, the attack can be performed remotely as long as the attacker can authenticate as a subscriber or higher and upload a file with a crafted filename. Successful exploitation would give the attacker full control over the server’s command line, leading to data exfiltration, site defacement, or further lateral movement.

Generated by OpenCVE AI on September 19, 2026 at 10:31 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade WP Photo Album Plus to any release newer than 9.2.09.002 that includes the fixed filename sanitization.
  • If an upgrade is not immediately possible, temporarily restrict file uploads for subscriber roles by adjusting the plugin’s settings or WordPress role capabilities to prevent the vulnerable upload path.
  • Consider disabling the ImageMagick processing feature or switching to a safer image processing library until the upgrade is applied.

Generated by OpenCVE AI on September 19, 2026 at 10:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 02:00:00 +0000

Type Values Removed Values Added
First Time appeared Opajaap
Opajaap wp Photo Album Plus
Wordpress
Wordpress wordpress
Vendors & Products Opajaap
Opajaap wp Photo Album Plus
Wordpress
Wordpress wordpress

Sat, 19 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sat, 19 Sep 2026 02:45:00 +0000

Type Values Removed Values Added
Description The WP Photo Album Plus plugin for WordPress is vulnerable to Remote Code Execution in all versions via the wppa_image_magick function. This is due to insufficient sanitization of the multipart upload filename before concatenation into an ImageMagick command string executed via exec(), with only escapeshellcmd() applied to the whole command rather than quoting individual arguments. This makes it possible for authenticated attackers, with subscriber-level access and above, to execute code on the server. escapeshellcmd() escapes shell metacharacters but does not prevent argument injection because spaces remain as argument separators, and the filename sanitization applied at the database layer is never applied to the physical temporary file path used for ImageMagick processing.
Title WP Photo Album Plus <= 9.2.09.002 - Authenticated (Subscriber+) Remote Code Execution via Multipart Upload Filename via ImageMagick Argument Injection
Weaknesses CWE-74
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Opajaap Wp Photo Album Plus
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-09-19T14:01:27.128Z

Reserved: 2026-09-09T15:10:14.345Z

Link: CVE-2026-87909

cve-icon Vulnrichment

Updated: 2026-09-19T13:58:05.859Z

cve-icon NVD

Status : Deferred

Published: 2026-09-19T03:17:15.853

Modified: 2026-09-21T13:33:33.387

Link: CVE-2026-87909

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T01:45:16Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')