CVE-2026-42656: WordPress Contest Gallery plugin <= 28.1.6 - Cross Site Scripting (XSS) vulnerability
Published Jun 15, 2026
·Updated
Subscriber Cross Site Scripting (XSS) in Contest Gallery <= 28.1.6 versions.
Affected Software
1 affected component
WordPress Contest Gallery<=28.1.6
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Contest Gallery Pluginto a version that resolves this vulnerability.Fixed in 29.0.0
Event History
Jun 15, 2026
CVE Published
via MITRE·08:18 PM
Data Sourced
via MITRE·08:18 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·09:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-42656?
The severity of CVE-2026-42656 is rated as medium with a score of 6.5.
2
How do I fix CVE-2026-42656?
To fix CVE-2026-42656, upgrade the WordPress Contest Gallery plugin to a version greater than 28.1.6.
3
What type of vulnerability is identified in CVE-2026-42656?
CVE-2026-42656 identifies a Cross Site Scripting (XSS) vulnerability.
4
Who is impacted by CVE-2026-42656?
Subscribers using versions of the Contest Gallery plugin up to 28.1.6 are impacted by CVE-2026-42656.
5
What is the nature of the attack vector for CVE-2026-42656?
CVE-2026-42656 can be exploited through user interaction due to the plugin's inadequate input validation.