Stored Cross-Site Scripting Vulnerability in Ecommerce Contest Gallery by WordPress
CVE-2025-7725
7.2HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 1 August 2025
What is CVE-2025-7725?
The Ecommerce Contest Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting attacks via its comment feature, affecting all versions up to and including 26.1.0. This vulnerability arises from inadequate input sanitization and output escaping. As a result, unauthenticated attackers can exploit this flaw to inject malicious web scripts into the pages, allowing the scripts to be executed whenever a user accesses the compromised page.
Affected Version(s)
Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal or Stripe, Social Share Buttons, OpenAI * <= 26.1.0