CVE-2026-6379

HIGH LAB

WP Photo Album Plus < 9.1.11.001 - Unauthenticated SQL Injection via 'wppa-supersearch' Parameter

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2026-6379. PoCs published by fearlessresponsesolution, dinosn.

AI-analyzed exploit summary This repository contains a functional exploit for CVE-2026-6379, an unauthenticated SQL injection vulnerability in WP Photo Album Plus < 9.1.11.001. The exploit includes a Docker-based lab environment and a Python script to demonstrate time-based blind SQL injection via the `wppa-supersearch` parameter.

Description

The WP Photo Album Plus WordPress plugin before 9.1.11.001 does not properly sanitize and escape a parameter before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks.

Exploits (2)

github WORKING POC
by fearlessresponsesolution · tsqlpoc
https://github.com/fearlessresponsesolution/cve-pocs/tree/master/pocs/CVE-2026-6379

This repository contains a functional exploit for CVE-2026-6379, an unauthenticated SQL injection vulnerability in WP Photo Album Plus < 9.1.11.001. The exploit includes a Docker-based lab environment and a Python script to demonstrate time-based blind SQL injection via the `wppa-supersearch` parameter.

Classification
Working Poc 100%
Attack Type
Sqli
Complexity
Moderate
Reliability
Reliable
Target: WP Photo Album Plus < 9.1.11.001
No auth needed
Prerequisites: Docker environment · WordPress instance with vulnerable plugin
devstral-2 · analyzed May 19, 2026 Full analysis →
github WORKING POC
by dinosn · pythonpoc
https://github.com/dinosn/cve-2026-6379

This repository contains a functional exploit for CVE-2026-6379, an unauthenticated SQL injection vulnerability in WP Photo Album Plus < 9.1.11.001. The exploit leverages time-based blind injection via the 'wppa-supersearch' parameter and includes a Docker lab for testing.

Classification
Working Poc 100%
Attack Type
Sqli
Complexity
Moderate
Reliability
Reliable
Target: WP Photo Album Plus < 9.1.11.001
No auth needed
Prerequisites: A WordPress site with the vulnerable WP Photo Album Plus plugin installed
devstral-2 · analyzed May 21, 2026 Full analysis →

References (1)

Core 1
Core References
Exploit exploit vdb-entry technical-description
https://wpscan.com/vulnerability/60b88fd2-4048-4773-b319-63caaf5bd8eb/

Scores

CVSS v3 8.6
EPSS 0.0008
EPSS Percentile 24.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Lab Environment

COMMUNITY
Community Lab
docker pull wordpress:6.5-php8.2-apache
docker pull wordpress:cli-php8.2

Details

CWE
CWE-89
Status published
Products (1)
None/WP Photo Album Plus < 9.1.11.001
Published May 18, 2026
Tracked Since May 18, 2026