Executive brief
Contest Gallery, a WordPress plugin used to manage photo and video competitions, contains a security flaw that allows attackers to inject malicious scripts into the website. If a site administrator or visitor interacts with a specially crafted link or page, the attacker could execute code in their browser, potentially leading to unauthorized actions, data theft, or website redirection. This vulnerability can be exploited by remote attackers without needing to log in to the site.
Technical details
A Cross-Site Scripting (XSS) vulnerability exists in the Contest Gallery plugin for WordPress (versions <= 30.0.6) due to improper neutralization of input during web page generation (CWE-79). The flaw allows an unauthenticated remote attacker to inject arbitrary web scripts or HTML. Exploitation requires a victim (typically a site administrator or visitor) to perform a specific action, such as clicking a malicious link or visiting a crafted page (User Interaction required). Successful exploitation can lead to session hijacking, unauthorized administrative actions, or the delivery of malicious payloads to other users. The issue is resolved in version 30.0.7.
Affected products
- Wasiliy Strecker Contest Gallery <= 30.0.6
Timeline
- 2026-07-16: disclosed: Reported by Jayant Kamble
- 2026-07-27: advisory: Published by Patchstack and NVD
- 2026-07-27: patched: Fixed in version 30.0.7