CVE-2026-78088
Received Received - Intake

Unauthenticated Arbitrary File Overwrite in Contest Gallery WordPress Plugin

Vulnerability report for CVE-2026-78088, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-16

Last updated on: 2026-09-16

Assigner: Wordfence

Description

The Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Overwrite in all versions up to, and including, 32.0.1 due to insufficient file path validation in the 'baseUrlForFacebook' parameter. This makes it possible for authenticated attackers, with subscriber-level access and above, to overwrite known files which may lead to remote code execution when certain preconditions are met.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-16
Last Modified
2026-09-16
Generated
2026-10-06
AI Q&A
2026-09-16
EPSS Evaluated
2026-10-05
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
contest_gallery upload_and_vote_photos_media_sell_with_paypal_and_stripe to 32.0.1 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-434 The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the Contest Gallery WordPress plugin. It allows unauthenticated attackers with subscriber-level access or higher to overwrite existing files on the server by exploiting insufficient validation of the 'baseUrlForFacebook' parameter. This could lead to remote code execution if certain conditions are met.

Impact Analysis

If exploited, this vulnerability could allow attackers to overwrite critical files on your WordPress site, potentially leading to complete system compromise. Attackers might gain control of your website, steal data, or use it for malicious purposes like hosting malware.

Mitigation Strategies

Update the Contest Gallery plugin to the latest version beyond 32.0.1 immediately. Remove or disable the plugin if no update is available. Restrict user roles to prevent subscriber-level access unless necessary.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-78088. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart