A vulnerability has been found in WP Photo Album Plus Plugin 9.1.11.0 on WordPress and classified as critical . The impacted element is an unknown function. Performing a manipulation results in sql injection. This vulnerability is reported as CVE-2026-6379 . The attack is possible to be carried out remotely. No exploit exists. The affected component should be upgraded.