CVE-2026-18048

WP Photo Album Plus < 9.2.07.002 - Unauthenticated Arbitrary ZIP File Deletion via delmyzip Path Traversal

The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not validate a client-controlled value used to build a file path in one of its public endpoint actions, and performs no authorisation check on it, allowing unauthenticated attackers to delete arbitrary ZIP archives on the server, including ones stored outside the web root.


We have discovered 4,022 live websites that are affected by CVE-2026-18048.

Run a Free Instant Scan




Affected Software

Product  Wp Photo Album Plus
Category Wordpress Plugins
Vulnerable Domains4,022 live websites (97% of Wp Photo Album Plus install base)
Vulnerable Versions
  • from 0 through 9.2.7.2
Vulnerable Versions Count142 versions ( 99% of all versions)


Common Weakness Enumeration

CWE-73 External Control of File Name or Path



Details

  • Published - Aug 12, 2026
  • Updated - Aug 12, 2026

Credits

  • Erwan LR (WPScan) (finder)
  • WPScan (coordinator)

Website Distribution by Country

Number of websites using CVE-2026-18048
United States1,152 websites



Germany570 websites
Netherlands507 websites
France326 websites
GB178 websites
Denmark142 websites
Italy122 websites
Canada89 websites
Switzerland80 websites
Sweden57 websites

Website Distribution by TLD

Number of websites using CVE-2026-18048
.com1,180 websites
.nl519 websites
.org444 websites
.de415 websites
.fr176 websites
.net116 websites
.co.uk93 websites
.it83 websites
.be67 websites
.ch61 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-18048

Top websites that are affected by CVE-2026-18048. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
**************.nl Netherlands***,***
********.org United States***,***
*******.de Germany***,***
********.no Norway***,***
*******.org Canada***,***
***********.com United States***,***
****.***.my Malaysia***,***
*********.com Luxembourg***,***
********************.org United States***,***
*****************.org United States***,***
See full domain list

FAQ

CVE-2026-18048 is External Control of File Name or Path in Wp Photo Album Plus
A total of 4,022 websites have been identified as vulnerable to CVE-2026-18048, based on global website indexing conducted by WebTechSurvey.
The Wp Photo Album Plus is affected by the CVE-2026-18048 vulnerability.
Wp Photo Album Plus versions up to 9.2.7.2 are vulnerable to CVE-2026-18048.
CVE-2026-18048 is resolved in version 9.2.7.2 of Wp Photo Album Plus.