A vulnerability classified as critical was found in Photo Album Plus Plugin up to 9.2.07.001 on WordPress. Affected is an unknown function. Executing a manipulation can lead to file inclusion. This vulnerability appears as CVE-2026-18048 . The attack may be performed from remote. There is no available exploit. Upgrading the affected component is advised.