A vulnerability has been found in WP Photo Album Plus Plugin 9.1.11.0 on WordPress and classified as critical. The impacted element is an unknown function. Performing a manipulation results in sql injection.
This vulnerability is reported as CVE-2026-6379. The attack is possible to be carried out remotely. No exploit exists.
The affected component should be upgraded.