Executive brief
Contest Gallery Pro, a WordPress plugin used to manage photo and video contests, contains a critical security flaw that allows unauthorized users to gain administrative control over a website. By exploiting this vulnerability, an attacker can elevate their permissions to a high-level account, potentially leading to full site takeover, data theft, or the installation of malicious software. This issue is particularly dangerous as it requires no prior account or user interaction to execute.
Technical details
A critical privilege escalation vulnerability (CWE-266) exists in the Contest Gallery Pro plugin for WordPress due to incorrect privilege assignment. The flaw allows an unauthenticated remote attacker to escalate their privileges, potentially gaining full administrative access to the affected WordPress site. The vulnerability is exploitable over the network with low complexity and requires no user interaction. The issue affects all versions up to and including 29.0.1; a fix is available in version 29.0.2.
Affected products
- Wasiliy Strecker / ContestGallery Contest Gallery Pro n/a through 29.0.1
Timeline
- 2026-04-17: other: Reported by researcher daroo
- 2026-05-17: advisory: Patchstack advisory published
- 2026-06-01: disclosed: NVD publication date
- 2026-05-17: patched: Version 29.0.2 released to address the vulnerability