CVE-2026-97303: WordPress Scratch & Win – Giveaways and Contests plugin <= 3.0.2 - Broken Access Control vulnerability
Missing Authorization vulnerability in Apps Mav Scratch & Win – Giveaways and Contests scratch-win-giveaways-for-website-facebook allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Scratch & Win – Giveaways and Contests: from n/a through 3.0.2.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
scratch-win-giveaways-for-website-facebookto a version that resolves this vulnerability.Fixed in 3.1.0
Event History
Frequently Asked Questions
Which installations should be treated as affected?
Installations running Scratch & Win – Giveaways and Contests version 3.0.2 or earlier should be treated as affected. The available data does not specify a lower affected version.
What access does an attacker need to exploit this issue?
The CVSS vector indicates that exploitation is network-accessible and requires low-level privileges. It does not require user interaction.