๐Ÿ” CVE Alert

CVE-2026-22485

MEDIUM 6.5

WordPress My Album Gallery plugin <= 1.0.4 - Arbitrary File Deletion vulnerability

CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
4th

Missing Authorization vulnerability in Ruhul Amin My Album Gallery my-album-gallery allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects My Album Gallery: from n/a through <= 1.0.4.

CWE CWE-862
Vendor ruhul amin
Product my album gallery
Published Mar 25, 2026
Last Updated Mar 26, 2026
Stay Ahead of the Next One

Get instant alerts for ruhul amin my album gallery

Be the first to know when new medium vulnerabilities affecting ruhul amin my album gallery are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Ruhul Amin / My Album Gallery
n/a โ‰ค <= 1.0.4

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
patchstack.com: https://patchstack.com/database/Wordpress/Plugin/my-album-gallery/vulnerability/wordpress-my-album-gallery-plugin-1-0-4-arbitrary-file-deletion-vulnerability?_s_id=cve

Credits

Jitlada | Patchstack Bug Bounty Program