Junglewise Threat Intelligence

CVE-2026-78088: Contest Gallery Arbitrary File Overwrite in baseUrlForFacebook parameter

CVE-2026-78088 · Severity: high · CVSS 8.8 · Published 2026-09-16

Vendors: WordPress.org.

Executive brief

Contest Gallery is a WordPress plugin that allows users to upload photos, manage contests, and accept payments. An unauthenticated attacker can overwrite arbitrary files on the server due to insufficient validation of the baseUrlForFacebook parameter, potentially leading to remote code execution and full site compromise.

Technical details

The vulnerability is an arbitrary file overwrite flaw in the Contest Gallery WordPress plugin affecting versions up to 32.0.1. The 'baseUrlForFacebook' parameter lacks sufficient path validation, allowing attackers with subscriber-level access or above to overwrite known files on the server. The attack vector is network-based and requires authenticated access at the subscriber level or higher. Successful exploitation can lead to remote code execution when certain preconditions are met, such as overwriting PHP files or configuration files. The vulnerability was patched in version 33.0.0.

Affected products

  • Wordpress.org Contest Gallery up to and including 32.0.1

Timeline

  • 2026-09-16: disclosed
  • 2026-09-16: patched: Fixed in version 33.0.0

References