CVE-2026-18962

WP Photo Album Plus < 9.2.09.002 - Subscriber+ Cross-Album File Upload via Missing Authorization

The WP Photo Album Plus WordPress plugin before 9.2.09.002 does not check that the current user is allowed to upload into the album they target when it processes a front-end upload, allowing any authenticated user, such as a Subscriber, to upload files into albums owned by other users or by the administrator. Exploitation requires the WP Photo Album Plus WordPress plugin before 9.2.09.002's front-end user upload feature to be enabled, which is not the default.


We have discovered 4,217 live websites that are affected by CVE-2026-18962.

Run a Free Instant Scan




Affected Software

Product  Wp Photo Album Plus
Category Wordpress Plugins
Vulnerable Domains4,217 live websites (100% of Wp Photo Album Plus install base)
Vulnerable Versions
  • from 0 through 9.2.9.2
Vulnerable Versions Count144 versions ( 100% of all versions)


Common Weakness Enumeration

CWE-639 Authorization Bypass Through User-Controlled Key



Details

  • Published - Aug 12, 2026
  • Updated - Aug 12, 2026

Credits

  • Farid Narimanov (finder)
  • WPScan (coordinator)

Website Distribution by Country

Number of websites using CVE-2026-18962
United States1,223 websites



Germany612 websites
Netherlands526 websites
France340 websites
GB185 websites
Denmark150 websites
Italy124 websites
Canada91 websites
Switzerland83 websites
Sweden60 websites

Website Distribution by TLD

Number of websites using CVE-2026-18962
.com1,234 websites
.nl541 websites
.org475 websites
.de442 websites
.fr180 websites
.net124 websites
.co.uk96 websites
.it84 websites
.be73 websites
.ch63 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-18962

Top websites that are affected by CVE-2026-18962. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*******.nl Germany***,***
**************.nl Netherlands***,***
********.org United States***,***
****.nl Germany***,***
************.org United States***,***
*******.de Germany***,***
*******.de Germany***,***
************.org United States***,***
********.no Norway***,***
********.*******.nl Germany***,***
See full domain list

FAQ

CVE-2026-18962 is Authorization Bypass Through User-Controlled Key in Wp Photo Album Plus
A total of 4,217 websites have been identified as vulnerable to CVE-2026-18962, based on global website indexing conducted by WebTechSurvey.
The Wp Photo Album Plus is affected by the CVE-2026-18962 vulnerability.
Wp Photo Album Plus versions up to 9.2.9.2 are vulnerable to CVE-2026-18962.
CVE-2026-18962 is resolved in version 9.2.9.2 of Wp Photo Album Plus.