Boletines de Vulnerabilidades

CVE-2026-6379

   
Software afectado WORDPRESS
 
The WP Photo Album Plus WordPress plugin before 9.1.11.001 does not properly sanitize and escape a parameter before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks.

Link:

https://nvd.nist.gov/vuln/detail/CVE-2026-6379