🔐 CVE Alert

CVE-2026-84047

HIGH 8.6

Album Cover Finder <= 0.7.0 - Unauthenticated SQLi via and_action

CVSS Score
8.6
EPSS Score
0.0%
EPSS Percentile
0th

The Album Cover Finder WordPress plugin through 0.7.0 does not properly sanitize and escape a parameter before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks.

Vendor unknown
Product album cover finder
Published Sep 12, 2026
Last Updated Sep 12, 2026
Stay Ahead of the Next One

Get instant alerts for unknown album cover finder

Be the first to know when new high vulnerabilities affecting unknown album cover finder are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

Unknown / Album Cover Finder
0 ≤ 0.7.0

References

NVD ↗ CVE.org ↗ EPSS Data ↗
wpscan.com: https://wpscan.com/vulnerability/eebacbae-4b25-45b5-96d9-f5ba28dfd825/

Credits

João Ramos Maciel WPScan