CVE-2026-6379 affects the WP Photo Album Plus WordPress plugin before version 9.1.11.001. The vulnerability is caused by improper sanitization and escaping of a parameter before it is incorporated into a SQL query. This results in a SQL injection condition that can be triggered remotely by unauthenticated attackers. Based on the provided information, the flaw is reachable without authentication or user interaction and exposes the application to attacker-controlled SQL query manipulation against the underlying database.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Repository is a self-contained exploit-and-lab kit for CVE-2026-6379, an unauthenticated SQL injection in the WordPress WP Photo Album Plus plugin. The repo has 9 files: documentation (README plus writeup/prompts), a Docker lab, and PoCs. The main exploit is pocs/exploit.py, a standalone Python script using requests to send crafted GET requests to a public WordPress page containing a [wppa] shortcode. It targets the wppa-supersearch parameter in the plugin's owner search branch and also supports a second patched sink via wppa-calendar=exifdtm and wppa-caldate. Exploitation is time-based blind SQLi: probe mode induces SLEEP delays to confirm vulnerability; version/user/hash modes perform boolean inference with IF(...,SLEEP(),0) and binary-search each byte to recover VERSION(), the first wp_users.user_login, and the first wp_users.user_pass hash. The exploit is operational rather than weaponized: it contains working extraction logic but no framework integration or customizable post-exploitation payload. Repository structure: lab/docker-compose.yml provisions MySQL 8.0, WordPress 6.5 (Apache/PHP 8.2), and a wp-cli installer container. lab/init/install.sh installs WordPress, downloads the vulnerable WPPA+ build from a GitHub tarball, activates it, and creates a public page with a [wppa] shortcode so the vulnerable code path is reachable without authentication. lab/setup.sh automates bring-up/teardown. pocs/test_oracle.sh validates the exploit end-to-end by probing the vulnerable state, upgrading the plugin to 9.1.11.001, confirming the probe fails, then restoring the vulnerable version. Documentation explains root cause, patched sinks, request format, and detection guidance. Main exploit capability: unauthenticated web attack against a public WordPress page. Required target conditions are specific: vulnerable WPPA+ version, shortcode-rendered page, and correct wppa-occur value. Successful exploitation yields a timing oracle and supports extraction of sensitive database-backed values, especially WordPress password hashes for offline cracking.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.