Junglewise Threat Intelligence

CVE-2026-42656: Wasiliy Strecker Contest Gallery XSS in WordPress plugin

CVE-2026-42656 · Severity: medium · CVSS 6.5 · Published 2026-06-15

Executive brief

The Contest Gallery plugin for WordPress, which is used to manage and display photo or video contests, contains a security flaw that allows users with basic 'Subscriber' accounts to inject malicious scripts into the website. If an administrator or another visitor views the affected page, these scripts could allow an attacker to redirect users to malicious sites, steal session information, or deface the website. This vulnerability could be used to compromise the integrity of the contest or the security of its participants.

Technical details

A Cross-Site Scripting (XSS) vulnerability exists in the Contest Gallery plugin for WordPress due to improper neutralization of user-supplied input during web page generation (CWE-79). The flaw allows an authenticated attacker with 'Subscriber' level privileges to inject malicious JavaScript payloads into the application. Successful exploitation requires a victim (such as an administrator) to interact with the affected component, at which point the script executes in the context of the victim's browser. This can lead to session hijacking, unauthorized actions on behalf of the victim, or redirection to external malicious domains. The issue is resolved in version 29.0.0.

Affected products

  • Wasiliy Strecker Contest Gallery <= 28.1.6

Timeline

  • 2026-03-22: other: Reported by researcher endy
  • 2026-04-29: advisory: Initial advisory published by Patchstack
  • 2026-04-29: patched: Version 29.0.0 released to address the vulnerability
  • 2026-06-15: disclosed: CVE published to NVD

References