The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not validate a client-controlled value used to build a file path in one of its public endpoint actions, and performs no authorisation check on it, allowing unauthenticated attackers to delete arbitrary ZIP archives on the server, including ones stored outside the web root.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
CVE-2026-18048 affects WP Photo Album Plus, a popular WordPress plugin, through an unauthenticated file deletion vulnerability in versions before 9.2.07.002. The flaw stems from insufficient input validation on a client-controlled file path parameter combined with a missing authorization check on a public endpoint action. This allows any unauthenticated attacker to construct malicious requests that delete arbitrary ZIP archives on the server, potentially including files outside the web root directory. Organizations running vulnerable versions face significant risk of data loss, service disruption, and potential exposure of sensitive backups or configuration files that administrators may have stored as compressed archives.
While this CVE currently maps to zero Casky skills and lacks MITRE ATT&CK technique classification, practitioners using Casky's platform would detect the underlying attack pattern through behavioral analysis of improper input handling and authorization bypass techniques. The vulnerability represents a combination of CWE-73 (External Control of File Name or Path) paired with missing access controls—patterns that Claude's extended reasoning can correlate across security skill libraries. Practitioners monitoring their WordPress environments would recognize suspicious patterns including unauthenticated POST/GET requests to the plugin's public actions with manipulated file path parameters, followed by unexpected ZIP file deletions in system logs. Immediate remediation requires upgrading to WP Photo Album Plus version 9.2.07.002 or later, and organizations should audit server logs for evidence of exploitation or suspicious file deletion activity.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-18048. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation