Junglewise Threat Intelligence

CVE-2026-42660: Wasiliy Strecker Contest Gallery sensitive data exposure

CVE-2026-42660 · Severity: medium · CVSS 6.5 · Published 2026-06-15

Executive brief

The Contest Gallery plugin for WordPress, which is used to manage and display photo or video contests, contains a security flaw that exposes sensitive information. An attacker with a basic 'Subscriber' account can access data that should normally be restricted to administrators. This exposure could lead to the theft of user details or other internal system information, potentially facilitating further attacks on the website.

Technical details

A sensitive data exposure vulnerability exists in the Contest Gallery plugin for WordPress (versions up to and including 28.1.7). The flaw is classified under CWE-497 (Exposure of Sensitive System Information to an Unauthorized Control Sphere). An attacker authenticated with Subscriber-level privileges can exploit this vulnerability over the network without user interaction. Successful exploitation allows the attacker to view sensitive information that is intended to be restricted to higher-privileged users. The issue is addressed in version 29.0.0.

Affected products

  • Wasiliy Strecker Contest Gallery <= 28.1.7

Timeline

  • 2026-03-26: other: Vulnerability reported by Jakub Herman
  • 2026-04-29: advisory: Patchstack advisory published
  • 2026-06-15: disclosed: NVD publication date
  • 2026-04-29: patched: Version 29.0.0 released to address the issue

References