{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/wp-photo-album-plus-all-versions/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:wppa:wp_photo_album_plus:*:*:*:*:*:wordpress:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-87909"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["WP Photo Album Plus (all versions)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["WordPress"],"content_html":"\u003cp\u003eThe WP Photo Album Plus plugin for WordPress is susceptible to a remote code execution vulnerability identified as CVE-2026-87909. The flaw exists within the wppa_image_magick function, which fails to correctly sanitize user-provided multipart upload filenames before passing them to the ImageMagick utility via the PHP exec() function.\u003c/p\u003e\n\u003cp\u003eAlthough the plugin employs escapeshellcmd() on the constructed command string, this mitigation is insufficient to prevent argument injection. Because spaces remain unescaped, an attacker can append malicious arguments to the ImageMagick command line. Furthermore, the file path handling logic bypasses database-layer sanitization, allowing the use of arbitrary physical paths for execution. Authenticated users with subscriber-level privileges or higher can leverage this flaw to run malicious code on the hosting server, potentially leading to full server compromise. The issue affects all versions of the plugin, necessitating immediate review and application of vendor-provided security patches or disabling the plugin until a fix is deployed.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows authenticated attackers to gain remote code execution with the permissions of the web server user. This could lead to sensitive data theft, complete site defacement, or lateral movement within the hosting environment. As this affects any WordPress site running this plugin, the attack surface is broad, and given the low privilege requirement (subscriber), the barrier to entry is minimal.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eIdentify all WordPress installations utilizing the WP Photo Album Plus plugin by scanning for active plugins in the administrative dashboard or checking filesystem plugin directories.\u003c/li\u003e\n\u003cli\u003eReview web server access logs for anomalous POST requests directed to the plugin's upload endpoints, specifically monitoring for unusual filename parameters or shell metacharacters.\u003c/li\u003e\n\u003cli\u003eDisable the WP Photo Album Plus plugin immediately if a security update from the developer is not yet available.\u003c/li\u003e\n\u003cli\u003eAudit server-side execution logs for processes spawned by the web server user (e.g., www-data) that were initiated by PHP, specifically those involving ImageMagick binaries (e.g., convert, mogrify).\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-19T04:09:02Z","date_published":"2026-09-19T04:09:02Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-87909/","summary":"The WP Photo Album Plus plugin for WordPress contains an RCE vulnerability (CVE-2026-87909) allowing authenticated attackers with subscriber-level access to execute arbitrary commands through improper sanitization of ImageMagick arguments.","title":"Remote Code Execution in WP Photo Album Plus Plugin","url":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-87909/"}],"language":"en","title":"CraftedSignal Threat Feed - WP Photo Album Plus (All Versions)","version":"https://jsonfeed.org/version/1.1"}