← WordPress Vulnerabilities
WordPress security by component

Album Cover Finder

Album Cover Finder (album-cover-finder) is a WordPress plugin with 1 published CVE record in this archive. The latest tracked vulnerability was published Sep 12, 2026; the highest published CVSS base score is 8.6.

Plugin slug: album-cover-finder

CVE-2026-84047: Album Cover Finder exposes unauthenticated SQL injection

Album Cover Finder through 0.7.0 inserts an unauthenticated caller-controlled parameter into a SQL query without sufficient sanitization or escaping. An attacker can alter the query and extract sensitive database data. The authoritative export does not identify the endpoint, parameter, query, or selected tables.

PublishedSep 12, 2026
Safe version guidanceSee mitigation notes
Published vulnerabilities for album-cover-finder
Safe version
Sep 12, 2026 CVE-2026-84047
Album Cover Finder exposes unauthenticated SQL injection
Album Cover Finder through 0.7.0 inserts an unauthenticated caller-controlled parameter into a SQL query without sufficient sanitization or escaping. An attacker can alter the query and extract sensitive database data. The authoritative export does not identify the endpoint, parameter, query, or selected tables.
See mitigation notes
CVE8.6
NVDPending