Impact
The photos, files, YouTube, Twitter, Instagram, TikTok, ecommerce Contest Gallery – Upload & Vote Photos, media, Sell with PayPal & Stripe plugin is vulnerable to stored cross‑site scripting via its Name and Comment fields when users post comments on gallery entries. Because the plugin does not sanitize or escape these inputs, an unauthenticated attacker can inject arbitrary scripts that will execute whenever a visitor accesses the page, as documented in the CVE description. The weakness is identified as CWE‑79.
Affected Systems
Any WordPress site that runs the Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe plugin in any version up to and including 26.0.0.1 is affected.
Risk and Exploitability
The CVSS score of 7.2 reflects a high impact, while the EPSS score of less than 1% indicates a low probability of exploitation at present. The vulnerability is not listed in CISA's KEV catalog. An attacker only needs web access to the plugin’s comment form and does not require authentication, making the attack vector web‑based unauthenticated.
OpenCVE Enrichment
EUVD