CVE-2026-84047
Album Cover Finder <= 0.7.0 - Unauthenticated SQLi via and_action
CVSS Score
8.6
EPSS Score
0.0%
EPSS Percentile
0th
The Album Cover Finder WordPress plugin through 0.7.0 does not properly sanitize and escape a parameter before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks.
| Vendor | unknown |
| Product | album cover finder |
| Published | Sep 12, 2026 |
| Last Updated | Sep 12, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown album cover finder
Be the first to know when new high vulnerabilities affecting unknown album cover finder are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
Unknown / Album Cover Finder
0 ≤ 0.7.0
References
Credits
João Ramos Maciel WPScan