A vulnerability was found in Photo Album Plus Plugin up to 9.2.04.003 on WordPress and classified as problematic . This vulnerability affects unknown code. Such manipulation leads to information disclosure. This vulnerability is uniquely identified as CVE-2026-18049 . The attack can be launched remotely. No exploit exists. It is suggested to upgrade the affected component.