PT-2026-93271 · WordPress · Contest Gallery

·

CVE-2026-78088

·

Published

2026-09-16

·

Updated

2026-09-16

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions The Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe plugin for WordPress versions prior to 32.0.2
Description Insufficient file path validation in the baseUrlForFacebook parameter allows authenticated attackers with subscriber-level access and above to perform an arbitrary file overwrite. This flaw can lead to remote code execution if specific preconditions are met.
Recommendations Update the plugin to a version newer than 32.0.1. Avoid using the baseUrlForFacebook parameter until the update is applied.

Fix

RCE

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-78088

Affected Products

Contest Gallery