CVE-2025-6716: Contest Gallery <= 26.0.8 - Authenticated (Author+) Stored Cross-Site Scripting
The Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal or Stripe, Social Share Buttons, OpenAI plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'upload[1][title]' parameter in all versions up to, and including, 26.0.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-6716?
CVE-2025-6716 has a severity rating of medium due to its potential for stored cross-site scripting attacks.
How do I fix CVE-2025-6716?
To fix CVE-2025-6716, you should update the Contest Gallery plugin to version 26.0.9 or later.
Which versions are affected by CVE-2025-6716?
CVE-2025-6716 affects all versions of Contest Gallery up to and including version 26.0.8.
What type of attack can CVE-2025-6716 facilitate?
CVE-2025-6716 can facilitate stored cross-site scripting (XSS) attacks via the 'upload[1][title]' parameter.
Is CVE-2025-6716 specific to any platform?
Yes, CVE-2025-6716 is specific to the Contest Gallery plugin used in WordPress.