The WP Photo Album Plus WordPress plugin before 9.2.09.002 does not check that the current user is allowed to upload into the album they target when it processes a front-end upload, allowing any authenticated user, such as a Subscriber, to upload files into albums owned by other users or by the administrator. Exploitation requires the WP Photo Album Plus WordPress plugin before 9.2.09.002's front-end user upload feature to be enabled, which is not the default.
We have discovered 4,217 live websites that are affected by CVE-2026-18962.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 4,217 live websites (100% of Wp Photo Album Plus install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 144 versions ( 100% of all versions) |
| 1,223 websites | |
| 612 websites | |
| 526 websites | |
| 340 websites | |
| 185 websites | |
| 150 websites | |
| 124 websites | |
| 91 websites | |
| 83 websites | |
| 60 websites |
| .com | 1,234 websites |
| .nl | 541 websites |
| .org | 475 websites |
| .de | 442 websites |
| .fr | 180 websites |
| .net | 124 websites |
| .co.uk | 96 websites |
| .it | 84 websites |
| .be | 73 websites |
| .ch | 63 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *******.nl | ***,*** | ||
| **************.nl | ***,*** | ||
| ********.org | ***,*** | ||
| ****.nl | ***,*** | ||
| ************.org | ***,*** | ||
| *******.de | ***,*** | ||
| *******.de | ***,*** | ||
| ************.org | ***,*** | ||
| ********.no | ***,*** | ||
| ********.*******.nl | ***,*** |
FAQ