PT-2026-93271 · WordPress · Contest Gallery
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
The Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe plugin for WordPress versions prior to 32.0.2
Description
Insufficient file path validation in the
baseUrlForFacebook parameter allows authenticated attackers with subscriber-level access and above to perform an arbitrary file overwrite. This flaw can lead to remote code execution if specific preconditions are met.Recommendations
Update the plugin to a version newer than 32.0.1.
Avoid using the
baseUrlForFacebook parameter until the update is applied.Fix
RCE
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Contest Gallery