CVE-2026-61986: WordPress Contest Gallery plugin <= 30.0.5 - Cross Site Scripting (XSS) vulnerability
Unauthenticated Cross Site Scripting (XSS) in Contest Gallery <= 30.0.5 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Contest Gallery Pluginto a version that resolves this vulnerability.Fixed in 30.0.6
Event History
Frequently Asked Questions
What does an attacker need to exploit this issue?
The vulnerability is unauthenticated, so the attacker does not need a WordPress account or other prior privileges. Exploitation does require user interaction, as indicated by the UI:R vector.
What impact could successful exploitation have?
The supplied CVSS vector indicates low confidentiality, integrity, and availability impact, with scope changed. In practice, the reported issue is cross-site scripting in affected Contest Gallery versions through 30.0.5.
Which installations should be treated as affected?
Installations using the WordPress Contest Gallery plugin at version 30.0.5 or earlier should be treated as affected based on the provided version range. The data does not state whether any particular plugin configuration is required.