Description
The Contest Gallery – Upload, Vote & Sell with PayPal and Stripe plugin for WordPress is vulnerable to CSV Injection in all versions up to, and including, 27.0.3 via gallery submissions. This makes it possible for unauthenticated attackers to embed untrusted input into exported CSV files, which can result in code execution when these files are downloaded and opened on a local system with a vulnerable configuration.
Published: 2025-10-11
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthenticated CSV injection leading to possible code execution via downloaded CSV files
Action: Apply Patch
AI Analysis

Impact

The Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe plugin for WordPress contains a CSV injection flaw in all releases up to and including 27.0.3. By submitting gallery entries that include malicious content, an attacker can insert exploit payloads into exported CSV files. When a victim downloads and opens these files on a system with a vulnerable spreadsheet configuration, the injected code may be executed. This weakness is identified as CWE‑1236.

Affected Systems

WordPress sites running the Contest Gallery plugin version 27.0.3 or earlier. The flaw exists in the core upload, vote, and sell functionality that generates CSV exports of gallery data.

Risk and Exploitability

The CVSS score of 4.3 indicates a low severity impact, and the EPSS score of less than 1% shows a very low likelihood of widespread exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers would need unauthenticated access to the site’s gallery submission process and a victim who opens the crafted CSV file locally. The potential impact is limited to end‑user code execution rather than direct server compromise, but depending on the victim’s system configuration the risk could be significant for individual users.

Generated by OpenCVE AI on April 22, 2026 at 13:10 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Contest Gallery plugin to version 28.0.0 or later to remove the CSV injection vulnerability.
  • If an immediate update is not possible, disable or restrict the CSV export feature so that only trusted administrators can generate CSV files.
  • Encourage users to treat downloaded CSV files with caution and, if feasible, configure WordPress or the server to sanitize or block execution of spreadsheet files containing potentially malicious content.

Generated by OpenCVE AI on April 22, 2026 at 13:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 20 Oct 2025 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Contest-gallery
Contest-gallery contest Gallery
Wordpress
Wordpress wordpress
Vendors & Products Contest-gallery
Contest-gallery contest Gallery
Wordpress
Wordpress wordpress

Tue, 14 Oct 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 11 Oct 2025 08:45:00 +0000

Type Values Removed Values Added
Description The Contest Gallery – Upload, Vote & Sell with PayPal and Stripe plugin for WordPress is vulnerable to CSV Injection in all versions up to, and including, 27.0.3 via gallery submissions. This makes it possible for unauthenticated attackers to embed untrusted input into exported CSV files, which can result in code execution when these files are downloaded and opened on a local system with a vulnerable configuration.
Title Contest Gallery – Upload, Vote & Sell with PayPal and Stripe <= 27.0.3 - Unauthenticated CSV Injection
Weaknesses CWE-1236
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Subscriptions

Contest-gallery Contest Gallery
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-04-08T17:11:00.252Z

Reserved: 2025-10-03T11:57:16.168Z

Link: CVE-2025-11254

cve-icon Vulnrichment

Updated: 2025-10-14T13:30:51.991Z

cve-icon NVD

Status : Deferred

Published: 2025-10-11T09:15:32.453

Modified: 2026-04-15T00:35:42.020

Link: CVE-2025-11254

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-22T13:15:17Z

Weaknesses