ZeroHour

CVE-2026-78088

large

Arbitrary File Overwrite in WordPress Contest Gallery Plugin (up to 32.0.1)

CVSS 3.1
8.8 high
EPSS
Published
()
Modified
AI analysis

The Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe plugin for WordPress contains an arbitrary file overwrite flaw in all versions up to and including 32.0.1, caused by insufficient file path validation of the 'baseUrlForFacebook' parameter. An attacker with only subscriber-level access or above (trivially obtained on sites with open registration) can send a crafted request to overwrite files at known locations on the server. Depending on which files are overwritten and whether certain preconditions are met, this can lead to remote code execution, site defacement, or destruction of critical files such as configuration. The vulnerability is rated high severity (CVSS 3.1: 8.8) and was assigned by Wordfence. No public proof-of-concept exists, it is not in the CISA Known Exploited Vulnerabilities catalog, and no exploitation has been reported in the wild.

What to do: Update Contest Gallery to the latest available version, which addresses the flaw (any release after 32.0.1). Until patched, consider deactivating the plugin or closing open user registration, since any subscriber-level account is sufficient to trigger the overwrite. Review web server and access logs for requests containing the 'baseUrlForFacebook' parameter and verify the integrity of files under the WordPress installation for unexpected modifications.

Affected
Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe (WordPress plugin)All versions up to and including 32.0.1
Estimated exposure
largeOn the order of tens of thousands of WordPress sites (roughly 30,000 based on the plugin's WordPress.org active-install count) — This is a popular WordPress gallery/voting plugin whose WordPress.org active-install count is in the tens of thousands, so exposure is estimated at roughly that many sites, not all of which will be vulnerable if already patched or no…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Overwrite in all versions up to, and including, 32.0.1 due to insufficient file path validation in the 'baseUrlForFacebook' parameter. This makes it possible for authenticated attackers, with subscriber-level access and above, to overwrite known files which may lead to remote code execution when certain preconditions are met.

Ecosystems
WordPress
Weakness
CWE-434
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.