CVE-2026-87909 | opajaap WP Photo Album Plus Plugin up to 9.2.09.002 on WordPress ImageMagick wppa_image_magick os command injection

SecurityVulns

A vulnerability, which was classified as critical, has been found in opajaap WP Photo Album Plus Plugin up to 9.2.09.002 on WordPress. This affects the function wppa_image_magick of the component ImageMagick Handler. The manipulation leads to os command injection.

This vulnerability is traded as CVE-2026-87909. It is possible to initiate the attack remotely. There is no exploit available.VulDB Recent EntriesRead More