Unauthenticated Cross Site Scripting in Contest Gallery Plugin from WordPress
CVE-2026-65447
7.1HIGH
What is CVE-2026-65447?
The Contest Gallery plugin for WordPress versions up to 30.0.6 is susceptible to an unauthenticated Cross Site Scripting (XSS) vulnerability. This flaw can allow attackers to inject malicious scripts into web pages viewed by users, potentially compromising users' sessions or redirecting users to malicious sites. It is crucial for administrators to update to the latest version of the plugin to protect against such security risks.
Affected Version(s)
Contest Gallery <= 30.0.6