Unauthenticated Arbitrary File Overwrite in Contest Gallery Plugin for WordPress
CVE-2026-78088
8.8HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 16 September 2026
What is CVE-2026-78088?
The Contest Gallery β Upload & Vote Photos, Media, Sell with PayPal & Stripe plugin for WordPress exhibits a vulnerability that allows unauthenticated users to overwrite files due to insufficient validation of the 'baseUrlForFacebook' parameter. This flaw can be exploited by users with subscriber-level access or higher, potentially leading to remote code execution if certain conditions are met. This makes it essential for users to ensure that they are running the latest version to mitigate this risk.
Affected Version(s)
Contest Gallery β Upload & Vote Photos, Media, Sell with PayPal & Stripe 0 <= 32.0.1