What the vulnerability does
01Description
Unrestricted Upload of File with Dangerous Type vulnerability in J.N. Breetvelt a.K.A. OpaJaap WP Photo Album Plus.This issue affects WP Photo Album Plus: from n/a before 8.6.03.005.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
What the vulnerability does
Unrestricted Upload of File with Dangerous Type vulnerability in J.N. Breetvelt a.K.A. OpaJaap WP Photo Album Plus.This issue affects WP Photo Album Plus: from n/a before 8.6.03.005.
Explanation of Vulnerability in Simple Terms
WP Photo Album Plus before version 8.6.03.005 allows authenticated users with low privileges to upload files without proper validation. An attacker can upload malicious files—including PHP code—that execute on the server. The vulnerability affects the entire site because uploaded files can be accessed and executed, potentially compromising all data and functionality.
What an attacker can do
Upload and execute malicious files (including PHP code) on the server.
Potential impact on your site
Complete site compromise: attackers can read/modify all data, create admin accounts, or take the site offline.
Conditions required to exploit
Attacker must have a low-privilege user account (e.g., subscriber or contributor role).
Key dates
External resources
Related vulnerabilities