HIGH 8.8 NVD
CVE-2026-78088
The Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Overwrite in a
The Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Overwrite in all versions up to, and including, 32.0.1 due to insufficient file path validation in the 'baseUrlForFacebook' parameter. This makes it possible for authenticated attackers, with subscriber-level access and above, to overwrite known files which may lead to remote code execution when certain preconditions are met.
References
- https://plugins.trac.wordpress.org/changeset?old_path=/contest-gallery/tags/32.0.1/v10/v10
- https://www.wordfence.com/threat-intel/vulnerabilities/id/af2115ba-5573-41ce-8d5a-58c57c65
This high severity vulnerability with a CVSS score of 8.8 was published on 2026-09-16 via NVD.
vulnfeed aggregates 14123 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.