CVE-2025-10383: Contest Gallery – Upload, Vote & Sell with PayPal and Stripe <= 27.0.2 - Authenticated (Author+) Stored Cross-Site Scripting
The Contest Gallery – Upload, Vote & Sell with PayPal and Stripe plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple form field parameters in all versions up to, and including, 27.0.2. This is due to insufficient input sanitization and output escaping on user-supplied attributes. This makes it possible for authenticated attackers, with author-level access or higher, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-10383?
CVE-2025-10383 is rated as a medium severity vulnerability due to its potential for stored cross-site scripting.
How do I fix CVE-2025-10383?
To fix CVE-2025-10383, update the Contest Gallery – Upload, Vote & Sell with PayPal and Stripe plugin to version 27.0.3 or later.
What types of vulnerabilities does CVE-2025-10383 encompass?
CVE-2025-10383 encompasses stored cross-site scripting vulnerabilities due to insufficient input sanitization.
Which versions are affected by CVE-2025-10383?
CVE-2025-10383 affects all versions of the Contest Gallery plugin up to and including 27.0.2.
What is the impact of exploiting CVE-2025-10383?
Exploiting CVE-2025-10383 can allow attackers to execute malicious scripts in the browsers of users visiting the affected site.