{"api_version":"1","generated_at":"2026-08-10T04:57:57+00:00","cve":"CVE-2026-17014","urls":{"html":"https://cve.report/CVE-2026-17014","api":"https://cve.report/api/cve/CVE-2026-17014.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-17014","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-17014"},"summary":{"title":"WP Photo Album Plus < 9.2.07.002 - Unauthenticated Export ZIP File Deletion via delexportzips","description":"The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not perform any capability or nonce check on one of its public REST endpoint actions, allowing unauthenticated users to delete the generated album export ZIP archives it stores.","state":"PUBLISHED","assigner":"WPScan","published_at":"2026-08-09 06:18:17","updated_at":"2026-08-09 06:18:17"},"problem_types":["CWE-73 External Control of File Name or Path"],"metrics":[],"references":[{"url":"https://wpscan.com/vulnerability/d45c05bb-9c9f-4ed0-b02e-f683a56ba0e1/","name":"https://wpscan.com/vulnerability/d45c05bb-9c9f-4ed0-b02e-f683a56ba0e1/","refsource":"contact@wpscan.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-17014","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-17014","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Unknown","product":"WP Photo Album Plus","version":"affected 9.2.07.002 semver","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"CNA","value":"Vaibhav Narkhede","lang":"en"},{"source":"CNA","value":"WPScan","lang":"en"}],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"17014","cve":"CVE-2026-17014","epss":"0.001450000","percentile":"0.042800000","score_date":"2026-08-09","updated_at":"2026-08-10 00:07:34"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"WP Photo Album Plus","vendor":"Unknown","versions":[{"lessThan":"9.2.07.002","status":"affected","version":"0","versionType":"semver"}]}],"credits":[{"lang":"en","type":"finder","value":"Vaibhav Narkhede"},{"lang":"en","type":"coordinator","value":"WPScan"}],"descriptions":[{"lang":"en","value":"The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not perform any capability or nonce check on one of its public REST endpoint actions, allowing unauthenticated users to delete the generated album export ZIP archives it stores."}],"problemTypes":[{"descriptions":[{"description":"CWE-73 External Control of File Name or Path","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-08-09T06:00:12.516Z","orgId":"1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81","shortName":"WPScan"},"references":[{"tags":["exploit","vdb-entry","technical-description"],"url":"https://wpscan.com/vulnerability/d45c05bb-9c9f-4ed0-b02e-f683a56ba0e1/"}],"source":{"discovery":"EXTERNAL"},"title":"WP Photo Album Plus < 9.2.07.002 - Unauthenticated Export ZIP File Deletion via delexportzips","x_generator":{"engine":"WPScan CVE Generator"}}},"cveMetadata":{"assignerOrgId":"1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81","assignerShortName":"WPScan","cveId":"CVE-2026-17014","datePublished":"2026-08-09T06:00:12.516Z","dateReserved":"2026-07-24T10:12:26.964Z","dateUpdated":"2026-08-09T06:00:12.516Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-08-09 06:18:17","lastModifiedDate":"2026-08-09 06:18:17","problem_types":["CWE-73 External Control of File Name or Path"],"metrics":[],"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"17014","Ordinal":"1","Title":"WP Photo Album Plus < 9.2.07.002 - Unauthenticated Export ZIP Fi","CVE":"CVE-2026-17014","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"17014","Ordinal":"1","NoteData":"The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not perform any capability or nonce check on one of its public REST endpoint actions, allowing unauthenticated users to delete the generated album export ZIP archives it stores.","Type":"Description","Title":"WP Photo Album Plus < 9.2.07.002 - Unauthenticated Export ZIP Fi"}]}}}