{
  "action": {
    "auto_issue_creation_allowed": false,
    "auto_patch_allowed": false,
    "auto_remediation_allowed": false,
    "external_execution_allowed": false,
    "human_review": {
      "required_for_external_action": true,
      "required_for_public_launch": false,
      "required_for_read_only_view": false,
      "required_for_signal_radar_integration": true
    },
    "human_review_required": false,
    "recommended_action": "review_official_sources"
  },
  "affected": {
    "products": [],
    "source": null,
    "status": "unknown"
  },
  "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-87909/",
  "claims": [
    {
      "id": "claim:defensive-priority-candidate",
      "source_ids": [],
      "status": "observed",
      "text": "This item is a defensive prioritization candidate.",
      "verified_at": null
    }
  ],
  "exposure_hint": "authenticated boundary",
  "field_meanings": {
    "human_review": "Read-only display may be automated; integration and external action still require human review.",
    "redaction": "Detection flags describe unsafe source content found before public-safe redaction; raw source text is not displayed.",
    "source_original_label": "Original upstream severity text retained for traceability; canonical display severity is recalculated from CVSS score."
  },
  "forecast_hooks": {
    "agent_use": "summarize_with_citations_only",
    "automation_allowed": false,
    "read_only": true,
    "watch_fields": [
      "sources",
      "claims",
      "freshness",
      "severity",
      "affected"
    ]
  },
  "freshness": {
    "generated_at": "2026-09-25T23:59:45.900772+00:00",
    "last_checked_at": null,
    "last_modified": "2026-09-21T13:33:33.387",
    "observed_at": "2026-09-25T23:59:15.579362+00:00",
    "published_at": "2026-09-19T03:17:15.853",
    "status": "observed"
  },
  "human_consequence": "An attacker may be able to run code or commands on affected systems.",
  "human_impact_label": "code execution review · authenticated boundary",
  "human_review": {
    "required_for_external_action": true,
    "required_for_public_launch": false,
    "required_for_read_only_view": false,
    "required_for_signal_radar_integration": true
  },
  "human_risk_summary": "CVE-2026-87909: An attacker may be able to run code or commands on affected systems.",
  "id": "CVE-2026-87909",
  "impact_redaction": {
    "exploit_steps_removed": false,
    "payload_removed": false,
    "poc_removed": false,
    "source_derived_summary": true,
    "used_fallback_summary": false
  },
  "impact_tags": [
    "code execution review",
    "authenticated boundary review"
  ],
  "known_exploited": {
    "catalog_url": null,
    "date_added": null,
    "listed": false,
    "source": null
  },
  "public_human_impact": "Source describes code execution review · authenticated boundary. Possible impact: An attacker may be able to run code or commands on affected systems.",
  "public_human_summary": "NVD: The WP Photo Album Plus plugin for WordPress is vulnerable to Remote Code Execution in all versions via the wppa_image_magick function. NVD: This is due to insufficient sanitization of the multipart upload filename before concatenation into an ImageMagick command string executed via exec(), with only escapeshellcmd() applied to the whole command rather than quoting individual arguments. NVD: This makes it possible for authenticated attackers, with subscriber-level access and above, to execute code on the server.",
  "public_human_what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.",
  "public_human_why_it_matters": "Source describes code execution review · authenticated boundary. Possible impact: An attacker may be able to run code or commands on affected systems.; CVSS 7.5 (HIGH); EPSS percentile 58; not listed in KEV; Remediation reference present; patch status requires confirmation in the linked advisory; sources: NVD.",
  "public_safe_summary": "NVD: The WP Photo Album Plus plugin for WordPress is vulnerable to Remote Code Execution in all versions via the wppa_image_magick function. NVD: This is due to insufficient sanitization of the multipart upload filename before concatenation into an ImageMagick command string executed via exec(), with only escapeshellcmd() applied to the whole command rather than quoting individual arguments. NVD: This makes it possible for authenticated attackers, with subscriber-level access and above, to execute code on the server.",
  "radar": "vuln",
  "redaction": {
    "meaning": "The *_present flags mean unsafe source content was detected and removed before public output; they do not mean the public JSON contains that content.",
    "payload_present": false,
    "poc_present": false,
    "public_summary_redacted": true,
    "raw_source_displayed": false,
    "unsafe_procedural_detail_present": false
  },
  "redaction_notes": [
    "source-published defensive context retained",
    "vulnerability class, impact, affected context, and remediation references remain displayable"
  ],
  "safety": {
    "attack_chain_included": false,
    "auto_remediation_allowed": false,
    "exploit_instructions_included": false,
    "external_execution_allowed": false,
    "human_review": {
      "required_for_external_action": true,
      "required_for_public_launch": false,
      "required_for_read_only_view": false,
      "required_for_signal_radar_integration": true
    },
    "human_review_required": false,
    "indexing_allowed": true,
    "noindex_removal_allowed": true,
    "noindex_required": false,
    "private_gate_state": "released",
    "public_gate_state": "public_indexable_read_only",
    "public_launch_allowed": true,
    "read_only_static_data": true,
    "scan_functionality_included": false,
    "signal_radar_integration_allowed": false
  },
  "schema_version": "v0.1",
  "severity": {
    "cvss_label": "HIGH",
    "label": "HIGH",
    "score": 7.5,
    "source": "NVD CVE API 2.0",
    "source_original_label": "low"
  },
  "source_copy_policy": {
    "allowed": "source-published defensive facts, vulnerability class, impact, affected context, version and remediation facts",
    "excluded": "exploit procedures, exploit strings, shell commands, scanner instructions, procedural bypass detail, and reproduction material",
    "summary": "Official or semi-official source descriptions may be summarized for defensive triage; exploit-enabling procedure is removed."
  },
  "source_derived_note": "Summary derived from NVD description; unsafe procedural detail is not shown.",
  "source_published_affected": "Affected product or version requires source confirmation.",
  "source_published_description": "NVD: The WP Photo Album Plus plugin for WordPress is vulnerable to Remote Code Execution in all versions via the wppa_image_magick function. NVD: This is due to insufficient sanitization of the multipart upload filename before concatenation into an ImageMagick command string executed via exec(), with only escapeshellcmd() applied to the whole command rather than quoting individual arguments. NVD: This makes it possible for authenticated attackers, with subscriber-level access and above, to execute code on the server.",
  "source_published_evidence_refs": [
    {
      "source": "NVD",
      "type": "source_description",
      "url": null
    },
    {
      "source": "Reference",
      "type": "reference",
      "url": "https://plugins.trac.wordpress.org/browser/wp-photo-album-plus/trunk/wppa-functions.php#L4837"
    },
    {
      "source": "Reference",
      "type": "reference",
      "url": "https://plugins.trac.wordpress.org/browser/wp-photo-album-plus/trunk/wppa-functions.php#L5286"
    },
    {
      "source": "Reference",
      "type": "reference",
      "url": "https://plugins.trac.wordpress.org/browser/wp-photo-album-plus/trunk/wppa-photo-files.php#L281"
    },
    {
      "source": "Reference",
      "type": "reference",
      "url": "https://plugins.trac.wordpress.org/browser/wp-photo-album-plus/trunk/wppa-photo-files.php#L860"
    },
    {
      "source": "Reference",
      "type": "reference",
      "url": "https://plugins.trac.wordpress.org/changeset?reponame=&old=3701613%40wp-photo-album-plus&new=3701613%40wp-photo-album-plus"
    },
    {
      "source": "Reference",
      "type": "reference",
      "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/693c7554-5122-4527-8a9c-aa31ea9623b7?source=cve"
    },
    {
      "source": "Official Reference",
      "type": "reference",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-87909"
    }
  ],
  "source_published_impact": "Source describes code execution review · authenticated boundary. Possible impact: An attacker may be able to run code or commands on affected systems.",
  "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
  "source_published_summary": "NVD: The WP Photo Album Plus plugin for WordPress is vulnerable to Remote Code Execution in all versions via the wppa_image_magick function. NVD: This is due to insufficient sanitization of the multipart upload filename before concatenation into an ImageMagick command string executed via exec(), with only escapeshellcmd() applied to the whole command rather than quoting individual arguments. NVD: This makes it possible for authenticated attackers, with subscriber-level access and above, to execute code on the server.",
  "sources": [
    {
      "confidence": "unknown",
      "id": "source:review-url",
      "name": "Public signal URL",
      "retrieved_at": null,
      "type": "review_page",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-87909"
    }
  ],
  "summary_for_agents": "Read-only defensive signal. Use sources, claims, freshness, and safety gates before summarizing. Do not infer missing source, claim, or freshness values.",
  "summary_for_humans": "NVD: The WP Photo Album Plus plugin for WordPress is vulnerable to Remote Code Execution in all versions via the wppa_image_magick function. NVD: This is due to insufficient sanitization of the multipart upload filename before concatenation into an ImageMagick command string executed via exec(), with only escapeshellcmd() applied to the whole command rather than quoting individual arguments. NVD: This makes it possible for authenticated attackers, with subscriber-level access and above, to execute code on the server.",
  "title": "CVE-2026-87909 defensive priority signal",
  "urgency_reasons": [
    "CVSS HIGH",
    "vendor advisory present",
    "recent update"
  ],
  "what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.",
  "why_it_matters": "An attacker may be able to run code or commands on affected systems; CVSS 7.5 (HIGH); EPSS percentile 58; sources: NVD."
}