CVE-2026-78088: Contest Gallery <= 32.0.1 - Unauthenticated Arbitrary File Upload via 'baseUrlForFacebook' Parameter
The Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Overwrite in all versions up to, and including, 32.0.1 due to insufficient file path validation in the 'baseUrlForFacebook' parameter. This makes it possible for authenticated attackers, with subscriber-level access and above, to overwrite known files which may lead to remote code execution when certain preconditions are met.
Affected Software
Event History
Frequently Asked Questions
Does exploitation require an account?
Yes. Exploitation requires authentication with at least subscriber-level access, despite the title’s reference to unauthenticated upload.
Which installations are affected?
All versions of the Contest Gallery plugin up to and including 32.0.1 are affected.
What could an attacker do after exploiting this issue?
An attacker can overwrite known files through insufficient path validation in the baseUrlForFacebook parameter. Remote code execution may result when additional, unspecified preconditions are met.