CVE-2026-17014 | Photo Album Plus Plugin up to 9.2.04.003 on WordPress Public Rest Endpoint file inclusion
A vulnerability was found in Photo Album Plus Plugin up to 9.2.04.003 on WordPress. It has been classified as critical. Affected by this issue is some unknown functionality of the component Public Rest Endpoint. The manipulation leads to file inclusion.
This vulnerability is referenced as CVE-2026-17014. Remote exploitation of the attack is possible. No exploit is available.
Upgrading the affected component is recommended.VulDB Recent EntriesRead More