CVE-2026-78088
The Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Overwrite in all versions up to, and including, 32.0.1 due to insufficient file path validation in the 'baseUrlForFacebook' parameter. This makes it possible for authenticated attackers, with subscriber-level access and above, to overwrite known files which may lead to remote code execution when certain preconditions are met.
Weakness
The Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Overwrite in all versions up to, and including, 32.0.1 due to insufficient file path validation in the 'baseUrlForFacebook' parameter. This makes it possible for authenticated attackers, with subscriber-level access and above, to overwrite known files which may lead to remote code execution when certain preconditions are met.
References
- https://plugins.trac.wordpress.org/changeset?old_path=/contest-gallery/tags/32.0.1/v10/v10-admin/gallery/change-gallery/1_content-fb-like.php&new_path=/contest-gallery/tags/33.0.0/v10/v10-admin/gallery/change-gallery/1_content-fb-like.php
- https://www.wordfence.com/threat-intel/vulnerabilities/id/af2115ba-5573-41ce-8d5a-58c57c65c75a?source=cve
Find the bug before an attacker does.
Sign in with GitHub and run your first audit in under a minute. The free plan needs no credit card.