Executive brief
A vulnerability exists in the Contest Gallery plugin for WordPress, which is used to manage and display photo or video contests. An unauthenticated attacker could exploit this flaw to manipulate input quantities, potentially affecting how contest data is processed or displayed. This could lead to minor data integrity issues within the plugin's functionality without requiring any user interaction.
Technical details
The Contest Gallery plugin for WordPress (versions up to and including 28.1.7) is vulnerable to an improper validation of specified quantity in input (CWE-1284). This issue allows a remote, unauthenticated attacker to submit malformed or unexpected numerical values through network requests. According to the CVSS vector, the attack has low complexity, requires no privileges, and no user interaction. The primary impact is on integrity (I:L), meaning an attacker could potentially modify certain data points or plugin behaviors related to quantity processing, though it does not grant access to sensitive information or impact service availability.
Affected products
- Contest Gallery Contest Gallery <= 28.1.7
Timeline
- 2026-06-15: disclosed
- 2026-06-15: advisory