CVE-2026-78088
largeArbitrary File Overwrite in WordPress Contest Gallery Plugin (up to 32.0.1)
The Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe plugin for WordPress contains an arbitrary file overwrite flaw in all versions up to and including 32.0.1, caused by insufficient file path validation of the 'baseUrlForFacebook' parameter. An attacker with only subscriber-level access or above (trivially obtained on sites with open registration) can send a crafted request to overwrite files at known locations on the server. Depending on which files are overwritten and whether certain preconditions are met, this can lead to remote code execution, site defacement, or destruction of critical files such as configuration. The vulnerability is rated high severity (CVSS 3.1: 8.8) and was assigned by Wordfence. No public proof-of-concept exists, it is not in the CISA Known Exploited Vulnerabilities catalog, and no exploitation has been reported in the wild.
What to do: Update Contest Gallery to the latest available version, which addresses the flaw (any release after 32.0.1). Until patched, consider deactivating the plugin or closing open user registration, since any subscriber-level account is sufficient to trigger the overwrite. Review web server and access logs for requests containing the 'baseUrlForFacebook' parameter and verify the integrity of files under the WordPress installation for unexpected modifications.
| Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe (WordPress plugin) | All versions up to and including 32.0.1 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
The Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Overwrite in all versions up to, and including, 32.0.1 due to insufficient file path validation in the 'baseUrlForFacebook' parameter. This makes it possible for authenticated attackers, with subscriber-level access and above, to overwrite known files which may lead to remote code execution when certain preconditions are met.
- Ecosystems
- WordPress
- Weakness
- CWE-434
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.