What the vulnerability does
01Description
Unrestricted Upload of File with Dangerous Type vulnerability in J.N. Breetvelt a.K.A. OpaJaap WP Photo Album Plus.This issue affects WP Photo Album Plus: from n/a through 8.7.01.001.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
What the vulnerability does
Unrestricted Upload of File with Dangerous Type vulnerability in J.N. Breetvelt a.K.A. OpaJaap WP Photo Album Plus.This issue affects WP Photo Album Plus: from n/a through 8.7.01.001.
Explanation of Vulnerability in Simple Terms
WP Photo Album Plus versions up to 8.7.01.001 allow unauthenticated attackers to upload files without restriction. An attacker can upload malicious files—including PHP scripts—directly to the site, gaining the ability to run their own code on the server. No user interaction or authentication is required. This affects all installations of the plugin.
What an attacker can do
Upload and execute malicious files, including PHP code, to take full control of the site.
Potential impact on your site
Complete site compromise: attackers can read/modify/delete all data, create admin accounts, or use the site to attack others.
Conditions required to exploit
Network access only; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities